Implement role authorization

This commit is contained in:
Stella Rouzi 2014-08-12 11:51:59 +03:00
parent 6755328c4c
commit e2fb434dc7
122 changed files with 1386 additions and 751 deletions

View file

@ -22,6 +22,8 @@ gem 'omniauth-google-oauth2'
# Use cancancan as authorization framework
gem 'cancancan'
# Use rolify to set roles
gem 'rolify'
# Use transitions as state machine
gem 'transitions', :require => %w( transitions active_record/transitions )

View file

@ -296,6 +296,7 @@ GEM
request_store (1.0.6)
rest-client (1.6.7)
mime-types (>= 1.16)
rolify (3.4.0)
rspec (3.0.0)
rspec-core (~> 3.0.0)
rspec-expectations (~> 3.0.0)
@ -441,6 +442,7 @@ DEPENDENCIES
rails-observers
rdoc-generator-fivefish
redcarpet
rolify
rspec-activemodel-mocks
rspec-rails
rubocop

View file

@ -1,8 +1,10 @@
module Admin
class CallforpapersController < ApplicationController
before_filter :verify_organizer
load_and_authorize_resource :conference, find_by: :short_title
# load_and_authorize_resource :cfp, class: 'CallForPapers', through: :conference
def show
authorize! :show, CallForPapers.new(conference_id: @conference.id)
@cfp = @conference.call_for_papers
if @cfp.nil?
@cfp = CallForPapers.new
@ -10,6 +12,7 @@ module Admin
end
def update
authorize! :update, @conference.call_for_papers
@cfp = @conference.call_for_papers
@cfp.assign_attributes(params[:call_for_papers])
send_mail_on_schedule_public = @cfp.notify_on_schedule_public?
@ -30,6 +33,7 @@ module Admin
end
def create
authorize! :update, CallForPapers.new(conference_id: @conference.id)
@cfp = CallForPapers.new(params[:call_for_papers])
if @cfp.valid?
@cfp.save

View file

@ -1,16 +1,15 @@
module Admin
class CampaignsController < ApplicationController
before_filter :verify_organizer
load_and_authorize_resource :conference, find_by: :short_title
load_and_authorize_resource :campaign, through: :conference
def index
@conference = Conference.find_by(short_title: params[:conference_id])
authorize! :show, Campaign.new(conference_id: @conference.id)
@campaigns = @conference.campaigns
end
def create
@conference = Conference.find_by(short_title: params[:conference_id])
@campaign = @conference.campaigns.new(params[:campaign])
@campaign.conference_id = @conference.id
@campaign.attributes = params[:campaign]
if @conference.save
redirect_to(admin_conference_campaigns_path(conference_id: @conference.short_title),
@ -23,19 +22,12 @@ module Admin
end
def new
@conference = Conference.find_by(short_title: params[:conference_id])
@campaign = @conference.campaigns.new
end
def edit
@conference = Conference.find_by(short_title: params[:conference_id])
@campaign = Campaign.find(params[:id])
end
def update
@conference = Conference.find_by(short_title: params[:conference_id])
@campaign = Campaign.find(params[:id])
if @campaign.update_attributes(params[:campaign])
redirect_to(admin_conference_campaigns_path(
conference_id: @conference.short_title),
@ -50,8 +42,6 @@ module Admin
end
def destroy
@conference = Conference.find_by(short_title: params[:conference_id])
@campaign = Campaign.find(params[:id])
if @campaign.destroy
redirect_to(admin_conference_campaigns_path(conference_id: @conference.short_title),
notice: "Campaign '#{@campaign.name}' successfully deleted.")

View file

@ -1,7 +1,7 @@
module Admin
class CommercialsController < ApplicationController
before_action :set_conference
before_action :set_commercial, only: [:edit, :update, :destroy]
load_and_authorize_resource :conference, find_by: :short_title
load_and_authorize_resource through: :conference
def index
@commercials = @conference.commercials
@ -43,14 +43,6 @@ module Admin
private
def set_commercial
@commercial = @conference.commercials.find(params[:id])
end
def set_conference
@conference = Conference.find_by(short_title: params[:conference_id])
end
def commercial_params
#params.require(:commercial).permit(:commercial_id, :commercial_type)
params[:commercial]

View file

@ -1,6 +1,6 @@
module Admin
class ConferenceController < ApplicationController
before_filter :verify_organizer
load_and_authorize_resource :conference, find_by: :short_title
def index
# Redirect to new form if there is no conference
@ -63,8 +63,11 @@ module Admin
def create
@conference = Conference.new(params[:conference])
if @conference.valid?
@conference.save
# user that creates the conference becomes organizer of that conference
current_user.add_role :organizer, @conference
redirect_to(admin_conference_path(id: @conference.short_title),
notice: 'Conference was successfully created.')
else
@ -108,6 +111,7 @@ module Admin
if @conference.update_attributes(params[:conference])
Mailbot.delay.conference_date_update_mail(@conference) if notify_on_conf_dates_updates
Mailbot.delay.conference_registration_date_update_mail(@conference) if notify_on_conf_reg_dates_updates
redirect_to(edit_admin_conference_path(id: @conference.short_title),
notice: 'Conference was successfully updated.')
else

View file

@ -1,33 +1,30 @@
module Admin
class ContactsController < ApplicationController
before_action :set_conference
before_action :set_conference
before_action :set_contact, only: [:edit, :update]
load_and_authorize_resource :conference, find_by: :short_title
load_and_authorize_resource through: :conference, singleton: true
# GET /:conference/contact/edit
def edit
# GET /:conference/contact
def show; end
# GET /:conference/contact/edit
def edit; end
# PATCH/PUT /:conference/contact
def update
if @contact.update(contact_params)
redirect_to admin_conference_contact_path, notice: 'Contact details were successfully updated.'
else
render :edit
end
end
# PATCH/PUT /:conference/contact
def update
if @contact.update(contact_params)
redirect_to edit_admin_conference_contact_path, notice: 'Contact details were successfully updated.'
else
render :edit
end
end
private
# Use callbacks to share common setup or constraints between actions.
def set_contact
@contact = @conference.contact
end
def set_conference
@conference = Conference.find_by(short_title: params[:conference_id])
end
# DELETE /:conference/contact
def destroy
@contact.destroy
redirect_to admin_conference_contacts_url, notice: 'Contact details were successfully destroyed.'
end
private
# Only allow a trusted parameter "white list" through.
def contact_params
# params.require(:contact).permit(:social_tag, :email, :facebook, :googleplus, :twitter, :instagram, :public)

View file

@ -1,6 +1,7 @@
module Admin
class DietchoicesController < ApplicationController
before_filter :verify_organizer
load_and_authorize_resource :conference, find_by: :short_title
load_and_authorize_resource :dietary_choice, through: :conference
def show
render :diets_list
@ -9,9 +10,9 @@ module Admin
def update
begin
@conference.update_attributes!(params[:conference])
redirect_to(admin_conference_dietary_list_path(conference_id: @conference.short_title), notice: 'Dietary choices were successfully updated.')
redirect_to(admin_conference_dietary_list_path(:conference_id => @conference.short_title), :notice => 'Dietary choices were successfully updated.')
rescue => e
redirect_to(admin_conference_dietary_list_path(conference_id: @conference.short_title), alert: "Dietary choices update failed: #{e.message}")
redirect_to(admin_conference_dietary_list_path(:conference_id => @conference.short_title), :alert => "Dietary choices update failed: #{e.message}")
end
end
end

View file

@ -1,9 +1,10 @@
module Admin
class DifficultyLevelsController < ApplicationController
before_filter :verify_organizer
load_and_authorize_resource :conference, find_by: :short_title
authorize_resource through: :conference
def index
@conference = Conference.find_by(short_title: params[:conference_id])
authorize! :index, DifficultyLevel.new(conference_id: @conference.id)
end
def update
@ -13,18 +14,18 @@ module Admin
@conference.use_difficulty_levels = false
@conference.save!
flash[:error] = "You cannot enable the usage of difficulty levels without having set any levels."
redirect_to(admin_conference_difficulty_levels_path(conference_id: @conference.short_title))
redirect_to(admin_conference_difficulty_levels_path(:conference_id => @conference.short_title))
rescue ActiveRecord::RecordInvalid
flash[:error] = "Something went wrong. Difficulty Levels update failed."
redirect_to(admin_conference_difficulty_levels_path(conference_id: @conference.short_title))
redirect_to(admin_conference_difficulty_levels_path(:conference_id => @conference.short_title))
end
else
flash[:notice] = "Difficulty Levels were successfully updated."
redirect_to(admin_conference_difficulty_levels_path(conference_id: @conference.short_title))
redirect_to(admin_conference_difficulty_levels_path(:conference_id => @conference.short_title))
end
else
flash[:error] = "Difficulty Levels update failed."
redirect_to(admin_conference_difficulty_levels_path(conference_id: @conference.short_title))
redirect_to(admin_conference_difficulty_levels_path(:conference_id => @conference.short_title))
end
end
end

View file

@ -1,6 +1,7 @@
module Admin
class EmailsController < ApplicationController
before_filter :verify_organizer
load_and_authorize_resource :conference, find_by: :short_title
load_and_authorize_resource class: EmailSettings
def update
@conference.email_settings.update_attributes(params[:email_settings])
@ -10,6 +11,7 @@ module Admin
end
def index
authorize! :index, @conference.email_settings
@settings = @conference.email_settings
end
end

View file

@ -0,0 +1,25 @@
module Admin
class EventTypesController < ApplicationController
load_and_authorize_resource :conference, find_by: :short_title
authorize_resource :event_type, through: :conference
def index
authorize! :index, EventType.new(conference_id: @conference.id)
end
def show
render :eventtypes
end
def update
@conference.update_attributes!(params[:conference])
redirect_to(admin_conference_event_types_path(
conference_id: @conference.short_title),
notice: 'Event types were successfully updated.')
rescue Exception => e
redirect_to(admin_conference_event_types_path(
conference_id: @conference.short_title),
alert: "Event types update failed: #{e.message}")
end
end
end

View file

@ -1,6 +1,7 @@
module Admin
class EventsController < ApplicationController
before_filter :verify_organizer
load_and_authorize_resource :conference, find_by: :short_title
load_and_authorize_resource :event, through: :conference
before_action :get_event, except: [:index, :create]
@ -13,6 +14,8 @@ module Admin
end
def index
authorize! :index, @conference.events.build
@conference = Conference.find_by(short_title: params[:conference_id])
@events = @conference.events
@tracks = @conference.tracks
@machine_states = @events.state_machine.states.map

View file

@ -1,16 +1,17 @@
module Admin
class LodgingsController < ApplicationController
before_filter :verify_organizer
load_and_authorize_resource :conference, find_by: :short_title
load_and_authorize_resource :venue, through: :conference, singleton: true
authorize_resource :lodging, through: :venue
def index
@venue = @conference.venue
authorize! :update, Lodging.new(venue_id: @venue.id)
end
def show
end
def update
@venue = @conference.venue
if @venue.update_attributes(params[:venue])
redirect_to(admin_conference_lodgings_path(conference_id: @conference.short_title),
notice: 'Lodgings were successfully updated.')

View file

@ -1,23 +1,24 @@
module Admin
class QuestionsController < ApplicationController
before_filter :verify_organizer
load_and_authorize_resource :conference, find_by: :short_title
load_and_authorize_resource through: :conference, except: [:new, :create]
def index
@conference = Conference.find_by(short_title: params[:conference_id])
@questions = Question.where(global: true).all | Question.where(conference_id: @conference.id)
authorize! :update, Question.new(conference_id: @conference.id)
@questions = Question.where(:global => true).all | Question.where(:conference_id => @conference.id)
@questions_conference = @conference.questions
@new_question = @conference.questions.new
end
def new
@conference = Conference.find_by(short_title: params[:conference_id])
@new_question = @conference.questions.new
@question = Question.new(conference_id: @conference.id)
authorize! :create, @question
end
def create
@conference = Conference.find_by(short_title: params[:conference_id])
@question = @conference.questions.new(params[:question])
@question.conference_id = @conference.id
authorize! :create, @question
respond_to do |format|
if @conference.save
@ -31,42 +32,33 @@ module Admin
# GET questions/1/edit
def edit
@conference = Conference.find_by(short_title: params[:conference_id])
@question = Question.find(params[:id])
if @question.global == true && !has_role?(current_user, "Admin")
redirect_to(admin_conference_questions_path(conference_id: @conference.short_title), alert: "Sorry, you cannot edit global questions. Create a new one.")
if @question.global == true && !(current_user.has_role? :organizer, @conference)
redirect_to(admin_conference_questions_path(:conference_id => @conference.short_title), :alert => "Sorry, you cannot edit global questions. Create a new one.")
end
end
# PUT questions/1
def update
@conference = Conference.find_by(short_title: params[:conference_id])
@question = Question.find(params[:id])
if @question.update_attributes(params[:question])
redirect_to(admin_conference_questions_path(conference_id: @conference.short_title), notice: "Question '#{@question.title}' for #{@conference.short_title} successfully updated.")
redirect_to(admin_conference_questions_path(:conference_id => @conference.short_title), :notice => "Question '#{@question.title}' for #{@conference.short_title} successfully updated.")
else
redirect_to(admin_conference_questions_path(conference_id: @conference.short_title), notice: "Update of questions for #{@conference.short_title} failed.")
redirect_to(admin_conference_questions_path(:conference_id => @conference.short_title), :notice => "Update of questions for #{@conference.short_title} failed.")
end
end
# Update questions used for the conference
def update_conference
@conference = Conference.find_by(short_title: params[:conference_id])
if @conference.update_attributes(params[:conference])
redirect_to(admin_conference_questions_path(conference_id: @conference.short_title), notice: "Questions for #{@conference.short_title} successfully updated.")
redirect_to(admin_conference_questions_path(:conference_id => @conference.short_title), :notice => "Questions for #{@conference.short_title} successfully updated.")
else
redirect_to(admin_conference_questions_path(conference_id: @conference.short_title), notice: "Update of questions for #{@conference.short_title} failed.")
redirect_to(admin_conference_questions_path(:conference_id => @conference.short_title), :notice => "Update of questions for #{@conference.short_title} failed.")
end
end
# DELETE questions/1
def destroy
if has_role?(current_user, "Admin")
@question = Question.find(params[:id])
if can? :destroy, @question
# Do not delete global questions
if @question.global == false
@ -74,12 +66,12 @@ module Admin
begin
Question.transaction do
@question.delete
@question.destroy
@question.answers.each do |a|
a.delete
end
flash[:notice] = "Deleted question: #{@question.title} and its answers: #{@question.answers.map {|a| a.title}.join ','}"
end
end
rescue ActiveRecord::RecordInvalid
flash[:error] = "Could not delete question."
end
@ -90,7 +82,7 @@ module Admin
flash[:error] = "You must be an admin to delete a question."
end
@questions = Question.where(global: true).all | Question.where(conference_id: @conference.id)
@questions = Question.where(:global => true).all | Question.where(:conference_id => @conference.id)
@questions_conference = @conference.questions
end
end

View file

@ -1,8 +1,10 @@
module Admin
class RegistrationsController < ApplicationController
before_filter :verify_organizer
load_and_authorize_resource :conference, find_by: :short_title
load_and_authorize_resource through: :conference
def index
authorize! :show, Registration.new(conference_id: @conference.id)
session[:return_to] ||= request.referer
@pdf_filename = "#{@conference.title}.pdf"
@registrations = @conference.registrations.includes(:user)
@ -12,7 +14,6 @@ module Admin
end
def change_field
@registration = Registration.find(params[:id])
field = params[:view_field]
if @registration.send(field.to_sym)
@registration.update_attribute(:"#{field}", 0)
@ -26,12 +27,10 @@ module Admin
end
def edit
@registration = @conference.registrations.where('id = ?', params[:id]).first
@user = User.where('id = ?', @registration.user_id).first
end
def update
@registration = @conference.registrations.where('id = ?', params[:id]).first
@user = User.where('id = ?', @registration.user_id).first
begin
@user.update_attributes!(params[:registration][:user_attributes])
@ -55,6 +54,7 @@ module Admin
def new
@user = User.new
@registration = @user.registrations.new
@registration.conference_id = @conference.id
@supporter_registration = @conference.supporter_registrations.new
end
@ -97,7 +97,7 @@ module Admin
end
def destroy
if has_role?(current_user, 'Admin')
if can? :destroy, @registration
registration = @conference.registrations.where(id: params[:id]).first
user = User.where('id = ?', registration.user_id).first

View file

@ -1,6 +1,11 @@
module Admin
class RoomsController < ApplicationController
before_filter :verify_organizer
load_and_authorize_resource :conference, find_by: :short_title
authorize_resource through: :conference
def index
authorize! :index, Room.new(conference_id: @conference.id)
end
def show
render :rooms_list

View file

@ -1,10 +1,14 @@
module Admin
class SchedulesController < ApplicationController
before_filter :verify_organizer
# By authorizing 'conference' resource, we can ensure there will be no unauthorized access to
# the schedule of a conference, which should not be accessed in the first place
load_and_authorize_resource :conference, find_by: :short_title
skip_before_filter :verify_authenticity_token, only: [:update]
layout 'schedule'
def show
authorize! :update, @conference.events.new
if @conference.nil?
redirect_to admin_conference_index_path
return
@ -14,6 +18,7 @@ module Admin
end
def update
authorize! :update, @conference.events.new
event = Event.where(guid: params[:event]).first
error_message = nil
if event.nil?

View file

@ -1,6 +1,7 @@
module Admin
class SocialEventsController < ApplicationController
before_filter :verify_organizer
load_and_authorize_resource :conference, find_by: :short_title
authorize_resource :social_event, through: :conference
def show
render :social_events_list
@ -8,9 +9,9 @@ module Admin
def update
if @conference.update_attributes(params[:conference])
redirect_to(admin_conference_social_events_path(conference_id: @conference.short_title), notice: 'Social events were successfully updated.')
redirect_to(admin_conference_social_events_path(:conference_id => @conference.short_title), :notice => 'Social events were successfully updated.')
else
redirect_to(admin_conference_social_events_path(conference_id: @conference.short_title), notice: 'Social events update failed.')
redirect_to(admin_conference_social_events_path(:conference_id => @conference.short_title), :notice => 'Social events update failed.')
end
end
end

View file

@ -1,15 +1,17 @@
module Admin
class SpeakersController < ApplicationController
before_filter :verify_organizer
load_and_authorize_resource :conference, find_by: :short_title
load_and_authorize_resource :event
respond_to :js, :html
def edit
@event = @conference.events.find(params[:event_id])
authorize! :update, @conference.events.new
@speaker = @event.event_users.where(event_role: 'speaker').first
end
def update
@event = @conference.events.find(params[:event_id])
authorize! :update, @conference.events.new
@speaker = @event.event_users.where(event_role: 'speaker').first
@speaker.user_id = params[:speaker][:user_id]
@speaker.save

View file

@ -1,6 +1,11 @@
module Admin
class SponsorsController < ApplicationController
before_filter :verify_organizer
load_and_authorize_resource :conference, find_by: :short_title
authorize_resource :sponsor, through: :conference
def index
authorize! :index, Sponsor.new(conference_id: @conference.id)
end
def update
if @conference.update_attributes(params[:conference])

View file

@ -1,6 +1,11 @@
module Admin
class SponsorshipLevelsController < ApplicationController
before_filter :verify_organizer
load_and_authorize_resource :conference, find_by: :short_title
authorize_resource through: :conference
def index
authorize! :index, SponsorshipLevel.new(conference_id: @conference.id)
end
def update
if @conference.update_attributes(params[:conference])

View file

@ -1,6 +1,7 @@
module Admin
class StatsController < ApplicationController
before_filter :verify_organizer
load_and_authorize_resource
load_and_authorize_resource :conference, find_by: :short_title
def index
@registrations = @conference.registrations.includes(:user)

View file

@ -1,6 +1,11 @@
module Admin
class SupporterLevelsController < ApplicationController
before_filter :verify_organizer
load_and_authorize_resource :conference, find_by: :short_title
authorize_resource through: :conference
def index
authorize! :update, SupporterLevel.new(conference_id: @conference.id)
end
def show
render :supporter_levels

View file

@ -1,6 +1,7 @@
module Admin
class SupportersController < ApplicationController
before_filter :verify_organizer
load_and_authorize_resource :conference, find_by: :short_title
load_and_authorize_resource through: :conference
def index
respond_to do |format|

View file

@ -1,11 +1,15 @@
module Admin
class TargetsController < ApplicationController
before_filter :verify_organizer
load_and_authorize_resource :conference, find_by: :short_title
authorize_resource through: :conference
def index
authorize! :index, Target.new(conference_id: @conference.id)
end
def update
authorize! :update, @conference => Target
if @conference.update_attributes(params[:conference])
redirect_to(admin_conference_targets_path(
conference_id: @conference.short_title),

View file

@ -1,6 +1,11 @@
module Admin
class TracksController < ApplicationController
before_filter :verify_organizer
load_and_authorize_resource :conference, find_by: :short_title
authorize_resource through: :conference
def index
authorize! :index, Track.new(conference_id: @conference.id)
end
def show
respond_to do |format|

View file

@ -1,6 +1,7 @@
module Admin
class UsersController < ApplicationController
before_filter :verify_admin
load_and_authorize_resource
def new
@user = User.new
end
@ -10,34 +11,37 @@ module Admin
end
def show
@user = User.find(params[:id])
# Variable @show_attributes holds the attributes that are visible for the 'show' action
# If you want to change the attributes that are shown in the 'show' action of users
# add/remove the attributes in the following string array
@show_attributes = %w(name email affiliation biography registered attended created_at
@show_attributes = %w(name email affiliation biography registered attended roles created_at
updated_at sign_in_count current_sign_in_at last_sign_in_at
current_sign_in_ip last_sign_in_ip)
end
def update
user = User.find(params[:id])
user.update_attributes!(params[:user])
redirect_to admin_users_path, notice: "Updated #{user.email}"
params[:user].delete :roles_attributes if params[:user]
@user.update_attributes!(params[:user])
redirect_to admin_users_path, notice: "Updated #{@user.email}"
end
def add_role
role = params[:user][:roles_attributes][:"0"]
@user.add_role role['name'].parameterize.underscore.to_sym, Conference.find(role['resource_id'])
respond_to do |format|
format.html
format.js
end
end
def edit
@user = User.find(params[:id])
end
def delete
@user = User.find(params[:id])
end
def destroy
@user = User.find(params[:id])
@user.destroy
redirect_to admin_users_path, notice: 'User got deleted'
redirect_to admin_users_path, notice: "User #{@user.name} (#{@user.email})got deleted"
end
end
end

View file

@ -1,6 +1,7 @@
module Admin
class VenueController < ApplicationController
before_filter :verify_organizer
load_and_authorize_resource :conference, find_by: :short_title
load_and_authorize_resource :venue, through: :conference, singleton: true
def index
end

View file

@ -1,26 +1,37 @@
module Admin
class VolunteersController < ApplicationController
load_and_authorize_resource :conference, find_by: :short_title
def index
@conference = Conference.find_by(short_title: params[:conference_id])
render :index
if (current_user.has_role? :organizer, @conference) || (current_user.has_role? :volunteer_coordinator, @conference)
render :index
else
authorize! :index, :volunteer
end
end
def show
@conference = Conference.find_by(short_title: params[:conference_id])
if @conference.use_vpositions
@volunteers = @conference.registrations.joins(:vchoices).uniq
if (current_user.has_role? :organizer, @conference) || (current_user.has_role? :volunteer_coordinator, @conference)
if @conference.use_vpositions
@volunteers = @conference.registrations.joins(:vchoices).uniq
else
@volunteers = @conference.registrations.where(:volunteer => true)
end
else
@volunteers = @conference.registrations.where(volunteer: true)
authorize! :index, :volunteer
end
end
def update
@conference = Conference.find_by(short_title: params[:conference_id])
begin
@conference.update_attributes!(params[:conference])
redirect_to(admin_conference_volunteers_info_path(conference_id: params[:conference_id]), notice: "Volunteering options were successfully updated.")
rescue => e
redirect_to(admin_conference_volunteers_info_path(conference_id: params[:conference_id]), alert: "Volunteering options update failed: #{e.message}")
if (current_user.has_role? :organizer, @conference) || (current_user.has_role? :volunteer_coordinator, @conference)
begin
@conference.update_attributes!(params[:conference])
redirect_to(admin_conference_volunteers_info_path(:conference_id => params[:conference_id]), :notice => "Volunteering options were successfully updated.")
rescue Exception => e
redirect_to(admin_conference_volunteers_info_path(:conference_id => params[:conference_id]), :alert => "Volunteering options update failed: #{e.message}")
end
else
authorize! :index, :volunteer
end
end
end

View file

@ -3,14 +3,17 @@ class ApplicationController < ActionController::Base
protect_from_forgery
before_filter :get_conferences
before_filter :store_location
before_filter :verify_user_admin
helper_method :date_string
# Ensure every controller authorizes resource or skips authorization (skip_authorization_check)
check_authorization unless: :devise_controller?
def store_location
session[:return_to] = request.fullpath if request.get? && controller_name != "user_sessions" && controller_name != "sessions"
end
def after_sign_in_path_for(resource)
if organizer_or_admin? &&
if (can? :view, Conference) &&
(!session[:return_to] ||
session[:return_to] &&
session[:return_to] == root_path)
@ -31,6 +34,16 @@ class ApplicationController < ActionController::Base
@conferences =Conference.all
end
def verify_user_admin
if self.class.to_s.split('::').first == 'Admin' && verify_user
unless (current_user.has_role? :organizer, :any) || (current_user.has_role? :cfp, :any) ||
(current_user.has_role? :info_desk, :any) ||
(current_user.has_role? :volunteers_coordinator, :any) || current_user.is_admin
raise CanCan::AccessDenied.new('You are not authorized to access this area!')
end
end
end
def verify_user
:authenticate_user!
@ -39,36 +52,17 @@ class ApplicationController < ActionController::Base
return false
end
@conference = Conference.find_by(short_title: params[:conference_id])
true
end
def organizer_or_admin?
has_role?(current_user, 'admin') || has_role?(current_user, 'organizer')
end
def verify_organizer
if !verify_user
return
end
## Todo simplify this
redirect_to root_path unless has_role?(current_user, 'admin') || has_role?(current_user, 'organizer')
end
def verify_admin
if !verify_user
return
end
redirect_to root_path unless has_role?(current_user, 'admin')
def current_ability
@current_ability ||= Ability.new(current_user)
end
rescue_from CanCan::AccessDenied do |exception|
Rails.logger.debug("Access denied!")
redirect_to root_path, alert: exception.message
end
helper_method :organizer_or_admin?
def not_found
raise ActionController::RoutingError.new('Not Found')

View file

@ -1,10 +1,11 @@
class CommercialsController < ApplicationController
before_action :set_conference
load_and_authorize_resource :conference, find_by: :short_title
before_action :set_event
before_action :set_commercial, only: [:edit, :update, :destroy]
load_and_authorize_resource through: @event, except: [:new, :create]
def new
@commercial = @event.commercials.build
authorize! :new, @commercial
end
def edit
@ -12,6 +13,7 @@ class CommercialsController < ApplicationController
def create
@commercial = @event.commercials.build(commercial_params)
authorize! :create, @commercial
if @commercial.save
redirect_to edit_conference_proposal_path(conference_id: @conference.short_title, id: @event.id),
@ -40,14 +42,6 @@ class CommercialsController < ApplicationController
private
def set_commercial
@commercial = @event.commercials.find(params[:id])
end
def set_conference
@conference = Conference.find_by(short_title: params[:conference_id])
end
def set_event
@event = @conference.events.find(params[:proposal_id])
end

View file

@ -1,7 +1,7 @@
class ConferenceController < ApplicationController
load_and_authorize_resource find_by: :short_title
def show
@conference = Conference.find_by_short_title(params[:id])
redirect_to root_path, notice: "Conference not ready yet!!" unless @conference.make_conference_public?
end
def subscribe
@ -41,7 +41,7 @@ class ConferenceController < ApplicationController
end
def gallery_photos
@photos = Conference.find_by_short_title(params[:id]).photos
@photos = @conference.photos
render "photos", formats: [:js]
end
end

View file

@ -1,9 +1,9 @@
class ConferenceRegistrationController < ApplicationController
before_filter :verify_user
load_resource :conference, find_by: :short_title
authorize_resource :conference_registration, class: Registration
def register
# TODO Figure out how to change the route's id from :id to :conference_id
@conference = Conference.find_by(short_title: params[:id])
@workshops = @conference.events.where('require_registration = ? AND state LIKE ?',
true, 'confirmed')
@user = current_user
@ -23,9 +23,8 @@ class ConferenceRegistrationController < ApplicationController
# TODO this is ugly
def update
conference = Conference.find_by(short_title: params[:id])
user = current_user
registration = user.registrations.where(conference_id: conference.id).first
registration = user.registrations.where(conference_id: @conference.id).first
update_registration = true
# First verify that the supporter code is legit
if !params[:registration][:supporter_registration_attributes].nil? &&
@ -35,7 +34,7 @@ class ConferenceRegistrationController < ApplicationController
if regs.count != 0
if regs.where(email: user.email).count == 0
redirect_to(register_conference_path(id: conference.short_title),
redirect_to(conference_register_path(conference_id: @conference.short_title),
alert: "This code is already in use.
Please contact #{conference.contact.email} for assistance.")
return
@ -50,7 +49,7 @@ class ConferenceRegistrationController < ApplicationController
supporter_reg = params[:registration][:supporter_registration_attributes]
params[:registration].delete :supporter_registration_attributes
registration = user.registrations.new(registration_params)
if conference.use_supporter_levels? && !supporter_reg.nil?
if @conference.use_supporter_levels? && !supporter_reg.nil?
if !supporter_reg[:id].blank?
# Means that their supporter registration was entered ahead of time, by an admin
registration.supporter_registration = SupporterRegistration.find(supporter_reg[:id])
@ -58,12 +57,12 @@ class ConferenceRegistrationController < ApplicationController
raise 'Invalid code'
end
else
registration.supporter_registration = conference.
registration.supporter_registration = @conference.
supporter_registrations.new(registration_params[:supporter_registration_attributes])
end
end
registration.conference_id = conference.id
registration.conference_id = @conference.id
registration.save!
if user.subscriptions.where(conference: conference).blank?
subscription = Subscription.new(conference_id: conference.id, user_id: user.id)
@ -74,7 +73,7 @@ class ConferenceRegistrationController < ApplicationController
end
rescue => e
Rails.logger.debug e.backtrace.join('\n')
redirect_to(register_conference_path(id: conference.short_title),
redirect_to(conference_register_path(conference_id: @conference.short_title),
alert: 'Registration failed:' + e.message)
return
end
@ -84,19 +83,18 @@ class ConferenceRegistrationController < ApplicationController
else
# Track ahoy event
ahoy.track 'Registered', title: 'New registration'
if conference.email_settings.send_on_registration?
Mailbot.delay.registration_mail(conference, current_user)
if @conference.email_settings.send_on_registration?
Mailbot.delay.registration_mail(@conference, current_user)
end
end
redirect_to(register_conference_path(id: conference.short_title),
redirect_to(conference_register_path(conference_id: @conference.short_title),
notice: redirect_message)
end
def unregister
conference = Conference.find_by(short_title: params[:id])
user = current_user
registration = user.registrations.where(conference_id: conference.id).first
subscription = user.subscriptions.where(conference: conference)
registration = user.registrations.where(conference_id: @conference.id).first
subscription = user.subscriptions.where(conference: @conference)
unless subscription.blank?
subscription.first.destroy
end

View file

@ -1,9 +1,11 @@
class EventAttachmentsController < ApplicationController
load_and_authorize_resource :conference, find_by: :short_title
load_and_authorize_resource :proposal, class: Event
load_and_authorize_resource :upload, class: EventAttachment, through: :proposal
before_filter :verify_user
skip_before_filter :verify_user, only: [:show]
def index
@proposal = Event.find(params[:proposal_id])
@uploads = @proposal.event_attachments
@uploads = @uploads.map{|upload| upload.to_jq_upload }
@ -14,9 +16,9 @@ class EventAttachmentsController < ApplicationController
end
def show
upload = EventAttachment.find(params[:id])
if upload.public?
send_file upload.attachment.path
if @upload.public?
send_file @upload.attachment.path
return
end
@ -26,7 +28,7 @@ class EventAttachmentsController < ApplicationController
end
if organizer_or_admin? || current_user == upload.event.submitter
send_file upload.attachment.path
send_file @upload.attachment.path
else
raise ActionController::RoutingError.new('Not Found')
end
@ -42,7 +44,6 @@ class EventAttachmentsController < ApplicationController
end
def edit
@upload = EventAttachment.find(params[:id])
end
def create
@ -50,7 +51,7 @@ class EventAttachmentsController < ApplicationController
params[:event_attachment][:public] = false
params[:event_attachment][:event_id] = params[:proposal_id]
if !organizer_or_admin?
if cannot? :create, EventAttachment
begin
current_user.events.find(params[:proposal_id])
rescue
@ -66,6 +67,7 @@ class EventAttachmentsController < ApplicationController
respond_to do |format|
if @upload.save
<<<<<<< HEAD
format.html do
render json: [@upload.to_jq_upload].to_json,
content_type: 'text/html',
@ -75,6 +77,15 @@ class EventAttachmentsController < ApplicationController
render json: [@upload.to_jq_upload].to_json, status: :created,
location: conference_proposal_event_attachment_path(@upload.event.conference.short_title, @upload.event, @upload)
end
=======
format.html {
render :json => [@upload.to_jq_upload].to_json,
:content_type => 'text/html',
:layout => false
}
format.json { render json: {files: [@upload.to_jq_upload]}, status: :created,
location: conference_proposal_event_attachment_path(@upload.event.conference.short_title, @upload.event, @upload) }
>>>>>>> authorization with cancancan
else
format.html { render action: "new" }
format.json { render json: @upload.errors, status: :unprocessable_entity }
@ -83,8 +94,6 @@ class EventAttachmentsController < ApplicationController
end
def update
@proposal = current_user.events.find(params[:proposal_id])
@upload = @proposal.event_attachments.find(params[:proposal_id])
respond_to do |format|
if @upload.update_attributes(params[:upload])
@ -98,9 +107,8 @@ class EventAttachmentsController < ApplicationController
end
def destroy
@proposal = Event.find(params[:proposal_id])
if organizer_or_admin? || current_user == @proposal.submitter
if can? :destroy, @proposal
@upload = @proposal.event_attachments.find(params[:id])
end

View file

@ -1,5 +1,6 @@
class HomeController < ApplicationController
before_filter :respond_to_options
skip_authorization_check
def index
@today = Date.current

View file

@ -1,22 +1,19 @@
class ProposalController < ApplicationController
before_filter :verify_user, except: [:show]
before_action :set_conference, only: [:show]
before_action :set_event, only: [:show, :edit, :update, :destroy, :confirm, :restart]
load_resource :conference, find_by: :short_title
load_and_authorize_resource :event, parent: false, through: :conference
def index
@events = current_user.proposals(@conference)
end
def show
authorize! :show, @event
# FIXME: We should show more than the first speaker
@speaker = @event.speakers.first || @event.submitter
end
def new
authorize! :new, Event
@url = conference_proposal_index_path(@conference.short_title)
@event = Event.new
end
def edit
@ -26,7 +23,6 @@ class ProposalController < ApplicationController
end
def create
authorize! :create, Event
@url = conference_proposal_index_path(@conference.short_title)
params[:event].delete :user
@ -53,7 +49,7 @@ class ProposalController < ApplicationController
registration = current_user.registrations.where(conference_id: @conference.id).first
ahoy.track 'Event submission', title: 'New submission'
if registration.nil?
redirect_to(register_conference_path(@conference.short_title),
redirect_to(conference_register_path(@conference.short_title),
alert: 'Event was successfully submitted.
You should register for the conference now.')
else
@ -120,7 +116,7 @@ class ProposalController < ApplicationController
end
if !@conference.user_registered?(current_user)
redirect_to(register_conference_path(@conference.short_title),
redirect_to(conference_register_path(@conference.short_title),
alert: 'The proposal was confirmed. Please register to attend the conference.')
return
end
@ -149,14 +145,4 @@ class ProposalController < ApplicationController
redirect_to(conference_proposal_index_path(conference_id: @conference.short_title),
notice: "The proposal was re-submitted. The #{@conference.short_title} organizers will review it again.")
end
private
def set_conference
@conference = Conference.find_by(short_title: params[:conference_id])
end
def set_event
@event = Event.find(params[:id])
end
end

View file

@ -1,4 +1,8 @@
class ScheduleController < ApplicationController
<<<<<<< HEAD
=======
authorize_resource class: false
>>>>>>> authorization with cancancan
layout "application"
def index

View file

@ -1,6 +1,7 @@
module Users
class OmniauthCallbacksController < Devise::OmniauthCallbacksController
skip_before_filter :verify_authenticity_token
skip_authorization_check
User.omniauth_providers.each do |provider|
define_method(provider) { handle(provider) }

View file

@ -137,14 +137,6 @@ module ApplicationHelper
render "shared/dynamic_association", association_name: association_name, title: title, f: form_builder, hint: options[:hint]
end
def has_role?(current_user, role)
if current_user.nil?
return false
end
return !!current_user.role?(role.to_s.camelize)
end
# Same as redirect_to(:back) if there is a valid HTTP referer, otherwise redirect_to()
def redirect_back_or_to(options = {}, response_status = {})
if request.env["HTTP_REFERER"]

View file

@ -2,16 +2,144 @@ class Ability
include CanCan::Ability
def initialize(user)
# guest user (not logged in)
user ||= User.new
if user.admin? || user.organizer?
# An admin can manage everything
can :manage, :all
# The first argument to `can` is the action you are giving the user permission to do.
# If you pass :manage it will apply to every action. Other common actions here are
# :read, :create, :update and :destroy.
#
# The second argument is the resource the user can perform the action on. If you pass
# :all it will apply to every resource. Otherwise pass a Ruby class of the resource.
#
# The third argument is an optional hash of conditions to further filter the objects.
# For example, here the user can only update published articles.
#
# can :update, Article, :published => true
#
# See the wiki for details: https://github.com/ryanb/cancan/wiki/Defining-Abilities
# Order Abilities
# (Check https://github.com/CanCanCommunity/cancancan/wiki/Ability-Precedence)
# Check roles of user, using rolify. Role name is *case sensitive*
# user.is_organizer? or user.has_role? :organizer
# user.is_cfp_of? Conference or user.has_role? :cfp, Conference
# user.is_info_desk_of? Conference
# user.is_volunteer_coordinator_of? Conference
# user.is_attendee_of? Conference
# The following is wrong because a user will only have 'cfp' role for a specific conference
# user.is_cfp? # This is always false
user ||= User.new # guest user (not logged in)
if user.new_record?
guest(user)
else
can [:update, :destroy], Event do |event|
event.users.include?(user)
roles = Role::ACTIONABLES.map {|i| i.parameterize.underscore}
if (user.roles.pluck(:name) & roles).empty? && !user.is_admin # User has no roles
signed_in(user)
else
user_with_roles(user)
end
can [:create, :read], Event
end
end
def user_with_roles(user)
conf_ids_for_organizer = []
venue_ids_for_organizer = []
conf_ids_for_cfp = []
venue_ids_for_cfp = []
conf_ids_for_info_desk = []
conf_ids_for_volunteer_coordinator = []
# Ids of all the conferences for which the user has an 'organizer' role
conf_ids_for_organizer =
Conference.with_role(:organizer, user).pluck(:id) if user.has_role? :organizer, :any
venue_ids_for_organizer =
Conference.with_role(:organizer, user).pluck(:venue_id) if user.has_role? :organizer, :any
conf_ids_for_cfp =
Conference.with_role(:cfp, user).pluck(:id) if user.has_role? :cfp, :any
venue_ids_for_cfp =
Conference.with_role(:cfp, user).pluck(:venue_id) if user.has_role? :cfp, :any
# Ids of all the conferences for which the user has an 'info_desk' role
conf_ids_for_info_desk =
Conference.with_role(:info_desk, user).pluck(:id) if user.has_role? :info_desk, :any
# Ids of all the conferences for which the user has a 'volunteer_coordinator' role
conf_ids_for_volunteer_coordinator =
Conference.with_role(:volunteer_coordinator, user).pluck(:id) if user.has_role? :volunteer_coordinator, :any
signed_in(user) # Inherit abilities from signed user
# User with role
can :manage, User if user.is_admin # ??? || (user.has_role? :organizer, :any)
can [:new, :create], Conference if user.is_admin || (user.has_role? :organizer, :any)
can [:index, :show, :gallery_photos], Conference
can :manage, Conference, id: conf_ids_for_organizer
# can :manage, Conference do |conference|
# conference.id = conf_ids_for_organizer
# end
can :manage, Venue, id: venue_ids_for_organizer
can :index, Venue, id: venue_ids_for_cfp
can :manage, Registration, conference_id: conf_ids_for_organizer + conf_ids_for_info_desk
can :manage, Question, conference_id: conf_ids_for_organizer + conf_ids_for_info_desk
can :manage, Vposition, conference_id: conf_ids_for_organizer + conf_ids_for_volunteer_coordinator
can :manage, Vday, conference_id: conf_ids_for_organizer + conf_ids_for_volunteer_coordinator
# The ability to manage an Event means that:
# the user can also edit the schedule and that
# the user can also vote
can :manage, Event, conference_id: conf_ids_for_organizer + conf_ids_for_cfp
can :create, Event
can :manage, CallForPapers, conference_id: conf_ids_for_organizer + conf_ids_for_cfp
can :manage, EventType, conference_id: conf_ids_for_organizer + conf_ids_for_cfp
can :manage, Track, conference_id: conf_ids_for_organizer + conf_ids_for_cfp
can :manage, DifficultyLevel, conference_id: conf_ids_for_organizer + conf_ids_for_cfp
can :manage, EmailSettings, conference_id: conf_ids_for_organizer + conf_ids_for_cfp
can :manage, Campaign, conference_id: conf_ids_for_organizer
can :manage, Lodging, venue_id: venue_ids_for_organizer
can :manage, Photo, conference_id: conf_ids_for_organizer
can :manage, Room, conference_id: conf_ids_for_organizer + conf_ids_for_cfp
can :manage, Sponsor, conference_id: conf_ids_for_organizer
can :manage, SponsorshipLevel, conference_id: conf_ids_for_organizer
can :manage, SupporterLevel, conference_id: conf_ids_for_organizer
can :manage, Target, conference_id: conf_ids_for_organizer
can :manage, Commercial#, commercialable_type: 'Conference', commercialable_id: conf_ids_for_organizer
can :index, Commercial, commercialable_type: 'Conference'
# Manage commercials for events that belong to a conference of which user is organizer
can :manage, Commercial, commercialable_type: 'Event', commercialable_id: Event.where(conference_id: conf_ids_for_organizer + conf_ids_for_cfp).pluck(:id)
can :manage, Contact, conference_id: conf_ids_for_organizer
can :manage, Campaign, conference_id: conf_ids_for_organizer
end
def guest(user)
## Abilities for everyone, even guests (not logged in users)
can [:show, :gallery_photos], Conference do |conference|
conference.make_conference_public == true
end
can :show, Event do |event|
event.state == 'confirmed'
end
can :index, :schedule # show?
end
def signed_in(user)
guest(user) # Inherits abilities of guest
# Conference Registration
can :manage, Registration, user_id: user.id
## Proposals
# Users can manage their own proposals
can :manage, Event, id: user.events.pluck(:id)
# Submit proposals only for conferences that are not over yet
can :create, Event, conference_id: Conference.where('end_date >= ?', Date.today).pluck(:id)
# Users can manage their own commercials
can :manage, Commercial, commercialable_type: 'Event', commercialable_id: user.events.pluck(:id)
# View commercials of confirmed events
can :show, Commercial, commercialable_type: 'Event', commercialable_id: Event.where(state: 'confirmed').pluck(:id)
can :manage, EventAttachment do |ea|
Event.find(ea.event_id).event_users.where(user_id: user.id).present?
end
can :create, EventAttachment
end
end

View file

@ -1,7 +1,7 @@
class CallForPapers < ActiveRecord::Base
attr_accessible :start_date, :end_date,
:description, :schedule_changes, :rating,
:schedule_public, :include_cfp_in_splash
:schedule_public, :include_cfp_in_splash, :conference_id
belongs_to :conference
validates_presence_of :start_date, :end_date

View file

@ -1,6 +1,6 @@
class Campaign < ActiveRecord::Base
attr_accessible :name, :utm_source, :utm_medium, :utm_term,
:utm_content, :utm_campaign, :target_ids
attr_accessible :name, :target_ids, :conference_id,
:utm_source, :utm_medium, :utm_term, :utm_content, :utm_campaign
validates :name, :utm_campaign, presence: true

View file

@ -4,6 +4,7 @@
class Conference < ActiveRecord::Base
require 'uri'
serialize :events_per_week, Hash
resourcify # Needed to call 'Conference.with_role' in /models/ability.rb
attr_accessible :title, :short_title, :timezone, :html_export_path,
:start_date, :end_date, :rooms_attributes, :tracks_attributes,

View file

@ -1,5 +1,5 @@
class DifficultyLevel < ActiveRecord::Base
attr_accessible :title, :description, :color
attr_accessible :title, :description, :color, :conference_id
belongs_to :conference
has_many :events

View file

@ -6,6 +6,7 @@ class EventAttachment < ActiveRecord::Base
has_attached_file :attachment, path: ":rails_root/storage/:rails_env/attachments/:id/:style/:basename.:extension"
include Rails.application.routes.url_helpers
do_not_validate_attachment_file_type :attachment
def to_jq_upload
{

View file

@ -1,5 +1,6 @@
class EventType < ActiveRecord::Base
attr_accessible :title, :length, :minimum_abstract_length, :maximum_abstract_length, :color
attr_accessible :title, :length, :minimum_abstract_length, :maximum_abstract_length, :color,
:conference_id
belongs_to :conference

View file

@ -1,5 +1,5 @@
class Lodging < ActiveRecord::Base
attr_accessible :name, :description, :photo, :website_link
attr_accessible :name, :description, :photo, :website_link, :venue_id
belongs_to :venue
has_attached_file :photo,
styles: { thumb: '100x100>', large: '300x300>' }

View file

@ -1,5 +1,5 @@
class Question < ActiveRecord::Base
attr_accessible :title, :global, :answers_attributes, :answer_ids, :question_type_id
attr_accessible :title, :global, :answers_attributes, :answer_ids, :question_type_id, :conference_id
belongs_to :question_type
has_and_belongs_to_many :conferences

View file

@ -1,4 +1,10 @@
class Role < ActiveRecord::Base
attr_accessible :name
attr_accessible :name, :description
has_and_belongs_to_many :users
belongs_to :resource, polymorphic: true
scopify
LABELS = ['Attendee', 'Volunteer', 'Speaker', 'Sponsor', 'Press', 'Keynote Speaker']
ACTIONABLES = ['Organizer', 'CfP', 'Info Desk', 'Volunteers Coordinator']
end

View file

@ -1,5 +1,5 @@
class Room < ActiveRecord::Base
attr_accessible :name, :size, :public
attr_accessible :name, :size, :public, :conference_id
belongs_to :conference
has_many :events

View file

@ -1,6 +1,5 @@
class Sponsor < ActiveRecord::Base
attr_accessible :name, :description, :website_url, :logo,
:sponsorship_level_id
attr_accessible :name, :description, :website_url, :logo, :sponsorship_level_id, :conference_id
belongs_to :sponsorship_level
belongs_to :conference
has_attached_file :logo,

View file

@ -1,5 +1,5 @@
class SponsorshipLevel < ActiveRecord::Base
attr_accessible :title
attr_accessible :title, :conference_id
validates_presence_of :title
belongs_to :conference
has_many :sponsors

View file

@ -2,5 +2,5 @@ class SupporterLevel < ActiveRecord::Base
belongs_to :conference
has_many :supporter_registrations
attr_accessible :conference, :title, :url, :description, :ticket_price
attr_accessible :conference, :title, :url, :description, :ticket_price, :conference_id
end

View file

@ -1,7 +1,7 @@
class Target < ActiveRecord::Base
include ActionView::Helpers::TextHelper
attr_accessible :due_date, :target_count, :unit
attr_accessible :due_date, :target_count, :unit, :conference_id
default_scope { order('due_date ASC') }

View file

@ -1,5 +1,5 @@
class Track < ActiveRecord::Base
attr_accessible :name, :description, :color
attr_accessible :name, :description, :color, :conference_id
belongs_to :conference

View file

@ -1,7 +1,10 @@
class User < ActiveRecord::Base
rolify
include Gravtastic
gravtastic size: 32
before_create :setup_role
# Include default devise modules. Others available are:
# :token_authenticatable, :confirmable,
# :lockable, :timeoutable and :omniauthable
@ -13,7 +16,7 @@ class User < ActiveRecord::Base
has_many :openids
attr_accessible :email, :password, :password_confirmation, :remember_me, :role_id, :role_ids,
:name, :email_public, :biography, :nickname, :affiliation
:name, :email_public, :biography, :nickname, :affiliation, :is_admin
has_many :event_users, dependent: :destroy
has_many :events, -> { uniq }, through: :event_users
@ -23,8 +26,6 @@ class User < ActiveRecord::Base
has_many :subscriptions, dependent: :destroy
accepts_nested_attributes_for :roles
before_create :setup_role
validates :name, presence: true
# Searches for user based on email. Returns found user or new user.
@ -47,26 +48,24 @@ class User < ActiveRecord::Base
user
end
def role?(role)
Rails.logger.debug('Checking role in user')
!!roles.find_by_name(role.to_s.downcase.camelize)
end
def admin?
role?('Admin')
end
def organizer?
role?('Organizer')
end
def get_roles
roles
end
def setup_role
roles << Role.where(name: 'Admin') if User.count == 0
roles << Role.where(name: 'Participant') if roles.empty?
self.is_admin = true if User.count == 0
end
# Gets the roles of the user, groups them by role.name and returns the resource(s) of each role
# ====Returns
# * +Hash+ * -> e.g. 'organizer' => "(conf1, conf2)"
def show_roles
result = {}
Role::ACTIONABLES.each do |role|
resources = self.roles.where(name: role.parameterize.underscore).map{ |myrole| Conference.find(myrole.resource_id).short_title }.join ', '
result[role.parameterize.underscore] = "(#{ resources })" unless resources.blank?
end
result
end
def self.prepare(params)

View file

@ -14,8 +14,11 @@
= commercial.commercial_type
.flexvideo
= render partial: 'shared/media_item', locals: { commercial_type: commercial.commercial_type, commercial_id: commercial.commercial_id }
= link_to 'Edit', edit_admin_conference_commercial_path(@conference.short_title, commercial.id), class: 'btn btn-primary'
= link_to 'Delete', admin_conference_commercial_path(@conference.short_title, commercial.id),
method: :delete, data: { confirm: 'Are you sure?' }, class: 'btn btn-danger'
%br
- if can? :update, commercial
= link_to 'Edit', edit_admin_conference_commercial_path(@conference.short_title, commercial.id), class: 'btn btn-primary'
- if can? :destroy, commercial
= link_to 'Delete', admin_conference_commercial_path(@conference.short_title, commercial.id),
method: :delete, data: { confirm: 'Are you sure?' }, class: 'btn btn-danger'
- if can? :create, @conference.commercials.new
%br
= link_to 'New Commercial', new_admin_conference_commercial_path, class: 'btn btn-primary'

View file

@ -0,0 +1,29 @@
.roles{ id: 'myroles' }
- unless @role.blank?
%p.text-muted
= @role.first.description
%hr
.row
.col-md-6
= semantic_form_for(:user, url: add_user_admin_conference_path(@conference.short_title, role: @selected), remote: true) do |f|
%h4
= f.input :email, label: "Add role '#{@selected}' to user: ", placeholder: "User's email"
= f.action :submit, as: :button, label: "Add User", button_html: {value: 'Add', class: 'btn btn-primary'}
.row
.col-md-12
%h3 Users with role #{@selected}
%table.table.table-striped.table-bordered.table-hover
%thead
%th ID
%th Name
%th Email
%tbody
- @role_users[@selection].each do |user|
%tr
%td
= link_to remove_user_admin_conference_path(@conference.short_title, user: user, role: @selected), method: :delete, remote: true, title: 'Remove user' do
%i{class: 'fa fa-times'}
= user.id
%td= user.name
%td= user.email

View file

@ -8,25 +8,49 @@
= conference_progress['process'] + '%'
%li{'class'=>class_for_todo(conference_progress['registration'])}
%span{'class'=>icon_for_todo(conference_progress['registration'])}
= link_to 'Set up registration period', edit_admin_conference_path(conference_progress['short_title'], :anchor => 'conference-end-datepicker')
- if can? :update, @conference.registrations.build
= link_to 'Set up registration period', edit_admin_conference_path(conference_progress['short_title'], :anchor => 'conference-end-datepicker')
- else
Set up registration period
%li{'class'=>class_for_todo(conference_progress['cfp'])}
%span{'class'=>icon_for_todo(conference_progress['cfp'])}
= link_to 'Set up call for papers', admin_conference_callforpapers_path(conference_progress['short_title'])
- if can? :update, CallForPapers.new(conference_id: @conference.id)
= link_to 'Set up call for papers', admin_conference_callforpapers_path(conference_progress['short_title'])
- else
Set up call for papers
%li{'class'=>class_for_todo(conference_progress['venue'])}
%span{'class'=>icon_for_todo(conference_progress['venue'])}
= link_to 'Add venue', admin_conference_venue_info_path(conference_progress['short_title'])
- if can? :update, @conference.venue
= link_to 'Add venue', admin_conference_venue_info_path(conference_progress['short_title'])
- else
Add venue
%li{'class'=>class_for_todo(conference_progress['rooms'])}
%span{'class'=>icon_for_todo(conference_progress['rooms'])}
= link_to 'Add rooms', admin_conference_rooms_path(conference_progress['short_title'])
- if can? :update, @conference.rooms.build
= link_to 'Add rooms', admin_conference_rooms_path(conference_progress['short_title'])
- else
Add rooms
%li{'class'=>class_for_todo(conference_progress['tracks'])}
%span{'class'=>icon_for_todo(conference_progress['tracks'])}
= link_to 'Add tracks', admin_conference_tracks_path(conference_progress['short_title'])
- if can? :update, @conference.tracks.build
= link_to 'Add tracks', admin_conference_tracks_path(conference_progress['short_title'])
- else
Add tracks
%li{'class'=>class_for_todo(conference_progress['event_types'])}
%span{'class'=>icon_for_todo(conference_progress['event_types'])}
= link_to 'Add event types', admin_conference_eventtypes_path(conference_progress['short_title'])
- if can? :update, @conference.event_types.build
= link_to 'Add event types', admin_conference_event_types_path(conference_progress['short_title'])
- else
Add event types
%li{'class'=>class_for_todo(conference_progress['difficulty_levels'])}
%span{'class'=>icon_for_todo(conference_progress['difficulty_levels'])}
= link_to 'Add difficulty levels', admin_conference_difficulty_levels_path(conference_progress['short_title'])
- if can? :update, @conference.difficulty_levels.build
= link_to 'Add difficulty levels', admin_conference_difficulty_levels_path(conference_progress['short_title'])
- else
Add difficulty levels
%li{class: class_for_todo(conference_progress['make_conference_public'])}
%span{'class'=>icon_for_todo(conference_progress['make_conference_public'])}
= link_to 'Make Splash Page Public for Visitors', edit_admin_conference_path(conference_progress['short_title'])
- if can? :update, @conference
= link_to 'Make Splash Page Public for Visitors', edit_admin_conference_path(conference_progress['short_title'])
- else
Make Splash Page Public for Visitors

View file

@ -0,0 +1,22 @@
.row
.col-md-6
= semantic_form_for(:user, url: roles_admin_conference_path(@conference.short_title), remote: true) do |f|
%h4
= f.input :roles, collection: @roles, label: 'Show users for role: '
= render partial: 'roles'
:javascript
$("#user_roles_input").change(function () {
var url = document.forms[0].action;
var selected_role = $(this).find('option:selected').attr('value');
$.ajax({
url: url,
type: "POST",
data: {user: { roles: selected_role } },
dataType: "script"
});
});

View file

@ -0,0 +1 @@
$('#myroles').html("<%= escape_javascript(render partial: 'roles').html_safe %>");

View file

@ -1,5 +1,5 @@
.row
.col-md-8
= semantic_form_for(@conference, url: admin_conference_eventtypes_path(@conference.short_title, @conference.event_types)) do |f|
= semantic_form_for(@conference, url: admin_conference_event_types_path(@conference.short_title, @conference.event_types)) do |f|
= dynamic_association :event_types, "Event Types", f
= f.action :submit, :as => :button, :button_html => {:class => "btn btn-primary"}

View file

@ -18,11 +18,11 @@
= ','
= label_tag dom_id(q), "Answers: #{q.answers.map {|a| a.title}.join(', ')}"
%td= link_to 'Edit', edit_admin_conference_question_path(@conference.short_title, q),
class: 'btn btn-primary',
disabled: q.global == true && !has_role?(current_user, 'Admin')
- if can? :update, q
%td= link_to 'Edit', edit_admin_conference_question_path(@conference.short_title, q),
class: 'btn btn-primary', disabled: q.global == true
%td= link_to 'Delete', admin_conference_question_path(@conference.short_title, q),
method: :delete, remote: true, class: 'btn btn-danger',
confirm: "Delete question '#{q.title}'?",
disabled: q.global == true && !has_role?(current_user, "Admin")
- if can? :destroy, q
%td= link_to 'Delete', admin_conference_question_path(@conference.short_title, q),
method: :delete, remote: true, class: 'btn btn-danger',
confirm: "Delete question '#{q.title}'?", disabled: q.global == true

View file

@ -7,9 +7,11 @@
= "(#{@registrations.length})"
= " - Attended (#{@attended})"
.btn-group.pull-right
= link_to "New", new_admin_conference_registration_path(@conference.short_title), :class => "btn btn-default"
= link_to "Export PDF", admin_conference_registrations_path(@conference.short_title, :format => :pdf), :class => "btn btn-default"
= link_to "Export XLS", {:format => :xlsx}, :class => "btn btn-default"
- if can? :create, Registration
= link_to "New", new_admin_conference_registration_path(@conference.short_title), :class => "btn btn-default"
- if can? :read, Registration
= link_to "Export PDF", admin_conference_registrations_path(@conference.short_title, :format => :pdf), :class => "btn btn-default"
= link_to "Export XLS", {:format => :xlsx}, :class => "btn btn-default"
%table.table.table-bordered.table-striped.table-hover#registrations
%thead
%th

View file

@ -1,8 +1,14 @@
= semantic_form_for [:admin, @user] do |f|
= f.inputs "Basic Information" do
= f.inputs 'Basic Information' do
= f.input :is_admin, hint: 'An admin can create a new conference, manage users and make other users admins.'
= f.input :name, :as => :string
= f.input :email
= f.input :affiliation, :as => :string
= f.input :biography, :input_html => {:rows => 10}
= f.actions do
= f.action :submit, :button_html => {:class => "btn btn-primary"}
= f.input :affiliation, as: :string
= f.input :biography, input_html: { rows: 5, "onkeyup" => "word_count(this, 'biography-count', 150)" }
You have used
%span#biography-count #{@user.biography_word_count}
words. Biographies are limited to 150 words.
%br
%br
= f.actions do
= f.action :submit, button_html: { class: 'btn btn-primary' }

View file

@ -5,7 +5,7 @@
- if @users
= "(#{@users.length})"
= link_to "New User", new_admin_user_path, :class => "btn btn-success pull-right"
= link_to "New User", new_admin_user_path, class: 'btn btn-success pull-right'
.well
%table.table.table-striped.table-bordered.table-hover#users
%thead
@ -18,7 +18,7 @@
%th
%b Name
%th
%b # of Conference Registrations
%b Attended Conferences
%th
%b Roles
%th
@ -38,39 +38,24 @@
%td
= user.name
%td
= user.registrations.count
= user.registrations.where(attended: true).count
%td
.modal.fade{:id => "user-role-selection-#{user.id}", "role" => "dialog", "aria-hidden" => "true"}
.modal-dialog
.modal-content
.modal-header
%button{"type"=>"button", :class=>"close", "data-dismiss"=>"modal", "aria-hidden"=>"true"}
×
%h3{:id => "role-selector-header-#{user.id}"}
Modifying Roles
.modal-body
- if current_user == user
You cannot modify your own role!
%br
%button{:class=> "btn btn-danger", "data-dismiss"=> "modal", "aria-hidden"=>"true"}
Cancel
- else
= "Give #{user.name} (#{user.email}) the following roles:"
= semantic_form_for(user, :url => admin_user_path(user), :method => :put) do |f|
= f.input :roles, :label => false
%button{:class=> "btn btn-danger", "data-dismiss"=> "modal", "aria-hidden"=>"true"}
Cancel
= f.action :submit, :as => :button, :button_html => {:value => "Save", :class => "btn btn-primary"}
=link_to "#{user.roles.map { |role| role.name }.join ', '}", "#", "data-toggle" => "modal", "data-target" => "#user-role-selection-#{user.id}",id: "user-modify-role-#{user.id}"
%td
= link_to "Edit", edit_admin_user_path(user)
%td
= link_to "View", admin_user_path(user)
%td
- if current_user.id == user.id or user.role_ids.include? 3
=link_to 'Delete',admin_user_path(user), :method => :delete , :data => {:confirm => 'Are you sure ?'}, :disabled => true,:class => "btn btn-primary disabled btn-danger",:role => "button"
- else
=link_to 'Delete',admin_user_path(user), :method=> :delete , :data=> {:confirm => 'Are you sure ?'},:class => "btn btn-primary btn-danger"
- unless user.show_roles.blank?
= user.show_roles.first(2).map { |x| x[0].titleize + ' ' + x[1] }.join ', '
- if user.show_roles.count > 2
= '...'
- if can? :show, user
%td
= link_to "View", admin_user_path(user), class: 'btn btn-success'
- if can? :update, user
%td
= link_to "Edit", edit_admin_user_path(user), class: 'btn btn-primary'
- if can? :destroy, user
%td
- if current_user.id == user.id or user.role_ids.include? 3
=link_to 'Delete',admin_user_path(user), :method => :delete , :data => {:confirm => 'Are you sure ?'}, :disabled => true,:class => "btn btn-primary disabled btn-danger",:role => "button"
- else
=link_to 'Delete',admin_user_path(user), :method=> :delete , :data=> {:confirm => 'Are you sure ?'},:class => "btn btn-primary btn-danger"
:javascript

View file

@ -1,7 +1,11 @@
%table.table
- @show_attributes.each do |attr|
%tr
%td
%td{style: 'width:20%'}
%b
= attr.capitalize.gsub('_', ' ')
%td= @user.send(attr)
- if attr == 'roles'
%td
= @user.show_roles.map { |x| x[0].titleize + ' ' + x[1] }.join ', '
- else
%td= @user.send(attr)

View file

@ -13,7 +13,7 @@
-else
%h4 Registration is Closed, it was from #{ date_string(@conference.registration_start_date, @conference.registration_end_date) }
- if @conference.registration_open?
= link_to "Register for #{@conference.short_title}", register_conference_path(@conference.short_title), :class =>"btn btn-success btn-lg", target: '_blank'
= link_to "Register for #{@conference.short_title}", conference_register_path(@conference.short_title), :class =>"btn btn-success btn-lg", target: '_blank'
- if @conference.use_supporter_levels?
- if @conference.include_tickets_in_splash?
= render 'tickets'

View file

@ -1,6 +1,6 @@
.row
.col-md-12
= semantic_form_for(@registration, :url => register_conference_path(@conference.short_title), :html => { :method => :patch }) do |f|
= semantic_form_for(@registration, :url => conference_register_path(@conference.short_title), :html => { :method => :patch }) do |f|
.tabbable
%ul.nav.nav-tabs
%li.active
@ -16,7 +16,7 @@
= render 'conference_registration/volunteer', :f => f
- if @registered
= f.action :submit, :button_html => { :value => "Update Registration", :class => "btn btn-primary" }
= link_to "Unregister", register_conference_path(@conference.short_title),:method => :delete, :class => "btn btn-danger",
= link_to "Unregister", conference_register_path(@conference.short_title),:method => :delete, :class => "btn btn-danger",
:confirm => "Are you sure you want to unregister?"
- else
= f.action :submit, :button_html => { :value => "Register", :class => "btn btn-primary", id: 'register' }

View file

@ -31,9 +31,9 @@
= link_to "View Conference", conference_path(conference.short_title), :class =>"btn btn-default"
- if conference.registration_open?
- if conference.user_registered?(current_user)
= link_to "Modify Registration", register_conference_path(conference.short_title), :class =>"btn btn-default"
= link_to "Modify Registration", conference_register_path(conference.short_title), :class =>"btn btn-default"
- else
= link_to "Register", register_conference_path(conference.short_title), :class =>"btn btn-success"
= link_to "Register", conference_register_path(conference.short_title), :class =>"btn btn-success"
= link_to "Schedule", conference_schedule_path(conference.short_title), :class =>"btn btn-default" if conference.call_for_papers and conference.call_for_papers.schedule_public
- if !current_user.nil? && current_user.proposal_count(conference) > 0
= link_to "View My Proposals", conference_proposal_index_path(conference.short_title), :class =>"btn btn-default"

View file

@ -10,97 +10,129 @@
%span.glyphicon.glyphicon-home
All Conferences
- @conferences.each do |conference|
- if can? :show, conference
%li
= link_to(admin_conference_path(conference.short_title)) do
%span.glyphicon.glyphicon-cog
Manage
= conference.short_title
- if (current_user.is_admin) || (current_user.has_role? :organizer, :any)
%li
= link_to(admin_conference_path(conference.short_title)) do
%span.glyphicon.glyphicon-cog
Manage
= conference.short_title
%li
= link_to(new_admin_conference_path) do
%span.glyphicon.glyphicon-plus
New Conference
= link_to(new_admin_conference_path) do
%span.glyphicon.glyphicon-plus
New Conference
%hr
%li{:class=> "#{active_nav_li(admin_conference_path(@conference.short_title))} nav-header nav-header-bigger"}
= link_to(admin_conference_path(@conference.short_title)) do
%span.fa.fa-tachometer
Dashboard
%li{:class=> "#{active_nav_li(edit_admin_conference_path(@conference.short_title))}"}
= link_to(edit_admin_conference_path(@conference.short_title)) do
%span.fa.fa-home
Basics
%ul
%li{:class=> "#{active_nav_li(edit_admin_conference_contact_path(@conference.short_title))}"}
= link_to(edit_admin_conference_contact_path(@conference.short_title)) do
%span.fa.fa-envelope-o
Contact
%li{:class=> "#{active_nav_li(admin_conference_commercials_path(@conference.short_title))}"}
= link_to(admin_conference_commercials_path(@conference.short_title)) do
%span.fa.fa-film
Commercials
%li{:class=> "#{active_nav_li(admin_conference_photos_path(@conference.short_title))}"}
= link_to(admin_conference_photos_path(@conference.short_title)) do
%span.fa.fa-picture-o
Photos
%li{:class=> active_nav_li(admin_conference_events_path(@conference.short_title))}
= link_to(admin_conference_events_path(@conference.short_title)) do
%span.glyphicon.glyphicon-comment
Events
%li{:class=> active_nav_li(admin_conference_registrations_path(@conference.short_title))}
= link_to(admin_conference_registrations_path(@conference.short_title)) do
%span.glyphicon.glyphicon-user
Registrations
%li{class: active_nav_li(admin_conference_schedule_path(@conference.short_title))}
= link_to(admin_conference_schedule_path(@conference.short_title), target: '_blank') do
%span.glyphicon.glyphicon-calendar
Schedule
%li{class: active_nav_li(admin_conference_campaigns_path(@conference.short_title))}
= link_to(admin_conference_campaigns_path(@conference.short_title)) do
%span.glyphicon.glyphicon-bullhorn
Campaigns
- if can? :show, @conference
%li{:class=> "#{active_nav_li(admin_conference_path(@conference.short_title))} nav-header nav-header-bigger"}
= link_to(admin_conference_path(@conference.short_title)) do
%span.fa.fa-tachometer
Dashboard
- if can? :update, @conference
%li{:class=> "#{active_nav_li(edit_admin_conference_path(@conference.short_title))}"}
= link_to(edit_admin_conference_path(@conference.short_title)) do
%span.fa.fa-home
Basics
- if can? :update, Contact.new(conference_id: @conference.id)
%ul
%li{:class=> "#{active_nav_li(edit_admin_conference_contact_path(@conference.short_title))}"}
= link_to(edit_admin_conference_contact_path(@conference.short_title)) do
%span.fa.fa-envelope-o
Contact
- if can? :index, @conference.commercials.build
%li{:class=> "#{active_nav_li(admin_conference_commercials_path(@conference.short_title))}"}
= link_to(admin_conference_commercials_path(@conference.short_title)) do
%span.fa.fa-film
Commercials
- if can? :update, @conference.photos.build
%li{:class=> "#{active_nav_li(admin_conference_photos_path(@conference.short_title))}"}
= link_to(admin_conference_photos_path(@conference.short_title)) do
%span.fa.fa-picture-o
Photos
- if can? :update, @conference.events.build
%li{:class=> active_nav_li(admin_conference_events_path(@conference.short_title))}
= link_to(admin_conference_events_path(@conference.short_title)) do
%span.glyphicon.glyphicon-comment
Events
- if can? :update, Registration.new(conference_id: @conference.id)
%li{:class=> active_nav_li(admin_conference_registrations_path(@conference.short_title))}
= link_to(admin_conference_registrations_path(@conference.short_title)) do
%span.glyphicon.glyphicon-user
Registrations
- if can? :update, @conference.events.build
%li{class: active_nav_li(admin_conference_schedule_path(@conference.short_title))}
= link_to(admin_conference_schedule_path(@conference.short_title), target: '_blank') do
%span.glyphicon.glyphicon-calendar
Schedule
- if can? :update, @conference
%li{class: active_nav_li(admin_conference_campaigns_path(@conference.short_title))}
= link_to(admin_conference_campaigns_path(@conference.short_title)) do
%span.glyphicon.glyphicon-bullhorn
Campaigns
%hr
%li{:class=> "#{active_nav_li(admin_conference_targets_path(@conference.short_title))}"}
= link_to(admin_conference_targets_path(@conference.short_title)) do
%span.glyphicon.glyphicon-flag
Targets
%li{:class=> "#{active_nav_li(admin_conference_venue_info_path(@conference.short_title))} myAccordion"}
= link_to(admin_conference_venue_info_path(@conference.short_title)) do
%span.glyphicon.glyphicon-road
Venue
%span.small.glyphicon.glyphicon-chevron-right
%ul.nav.nav-stacked.nav-pills.small.collapse.subNav
%li{:class=> active_nav_li(admin_conference_rooms_path(@conference.short_title))}
= link_to 'Rooms', admin_conference_rooms_path(@conference.short_title)
%li{ class: active_nav_li(admin_conference_lodgings_path(@conference.short_title)) }
= link_to 'Lodgings', admin_conference_lodgings_path(@conference.short_title)
%li{:class=> "#{active_nav_li(admin_conference_sponsorship_levels_path(@conference.short_title))} myAccordion" }
= link_to(admin_conference_sponsorship_levels_path(@conference.short_title)) do
%span.glyphicon.glyphicon-star
Sponsorship
%span.small.glyphicon.glyphicon-chevron-right
%ul.nav.nav-stacked.nav-pills.small.collapse.subNav
%li{:class=> active_nav_li(admin_conference_sponsors_path(@conference.short_title))}
= link_to 'Sponsors', admin_conference_sponsors_path(@conference.short_title)
%li{ class: active_nav_li(admin_conference_supporter_levels_path(@conference.short_title)) }
= link_to(admin_conference_supporter_levels_path(@conference.short_title)) do
%span.glyphicon.glyphicon-usd
Supporter Levels
%li{:class=> active_nav_li(admin_conference_emails_path(@conference.short_title))}
= link_to(admin_conference_emails_path(@conference.short_title)) do
%span.glyphicon.glyphicon-envelope
E-Mails
%li{:class=> "#{active_nav_li(admin_conference_callforpapers_path(@conference.short_title))} myAccordion"}
= link_to(admin_conference_callforpapers_path(@conference.short_title)) do
%span.glyphicon.glyphicon-comment
Call for papers
%span.small.glyphicon.glyphicon-chevron-right
%ul.nav.nav-stacked.nav-pills.small.collapse.subNav
%li{:class=> active_nav_li(admin_conference_tracks_path(@conference.short_title))}
= link_to 'Tracks', admin_conference_tracks_path(@conference.short_title)
%li{:class=> active_nav_li(admin_conference_eventtypes_path(@conference.short_title))}
= link_to 'Event types', admin_conference_eventtypes_path(@conference.short_title)
%li{:class=> active_nav_li(admin_conference_difficulty_levels_path(@conference.short_title))}
= link_to 'Difficulty levels', admin_conference_difficulty_levels_path(@conference.short_title)
- if can? :update, @conference
%li{:class=> "#{active_nav_li(edit_admin_conference_path(@conference.short_title))} nav-header nav-header-bigger"}
= link_to(edit_admin_conference_path(@conference.short_title)) do
%span.glyphicon.glyphicon-cog
Settings
- if can? :update, @conference.targets.build
%li{:class=> "#{active_nav_li(admin_conference_targets_path(@conference.short_title))}"}
= link_to(admin_conference_targets_path(@conference.short_title)) do
%span.glyphicon.glyphicon-flag
Targets
- if can? :index, @conference.venue
%li{:class=> "#{active_nav_li(admin_conference_venue_info_path(@conference.short_title))} myAccordion"}
= link_to(admin_conference_venue_info_path(@conference.short_title)) do
%span.glyphicon.glyphicon-road
Venue
%span.small.glyphicon.glyphicon-chevron-right
%ul.nav.nav-stacked.nav-pills.small.collapse.subNav
- if can? :update, @conference.rooms.build
%li{:class=> active_nav_li(admin_conference_rooms_path(@conference.short_title))}
= link_to 'Rooms', admin_conference_rooms_path(@conference.short_title)
- if can? :update, @conference.venue.lodgings.build
%li{ class: active_nav_li(admin_conference_lodgings_path(@conference.short_title)) }
= link_to 'Lodgings', admin_conference_lodgings_path(@conference.short_title)
- if can? :update, @conference.sponsorship_levels.build
%li{:class=> "#{active_nav_li(admin_conference_sponsorship_levels_path(@conference.short_title))} myAccordion" }
= link_to(admin_conference_sponsorship_levels_path(@conference.short_title)) do
%span.glyphicon.glyphicon-star
Sponsorship
%span.small.glyphicon.glyphicon-chevron-right
%ul.nav.nav-stacked.nav-pills.small.collapse.subNav
- if can? :update, @conference.sponsors.build
%li{:class=> active_nav_li(admin_conference_sponsors_path(@conference.short_title))}
= link_to 'Sponsors', admin_conference_sponsors_path(@conference.short_title)
- if can? :update, @conference.supporter_levels.build
%li{ class: active_nav_li(admin_conference_supporter_levels_path(@conference.short_title)) }
= link_to(admin_conference_supporter_levels_path(@conference.short_title)) do
%span.glyphicon.glyphicon-usd
Supporter Levels
- if can? :update, @conference.email_settings
%li{:class=> active_nav_li(admin_conference_emails_path(@conference.short_title))}
= link_to(admin_conference_emails_path(@conference.short_title)) do
%span.glyphicon.glyphicon-envelope
E-Mails
- if can? :update, CallForPapers.new(conference_id: @conference.id)
%li{:class=> "#{active_nav_li(admin_conference_callforpapers_path(@conference.short_title))} myAccordion"}
= link_to(admin_conference_callforpapers_path(@conference.short_title)) do
%span.glyphicon.glyphicon-comment
Call for papers
%span.small.glyphicon.glyphicon-chevron-right
%ul.nav.nav-stacked.nav-pills.small.collapse.subNav
- if can? :update, @conference.tracks.build
%li{:class=> active_nav_li(admin_conference_tracks_path(@conference.short_title))}
= link_to 'Tracks', admin_conference_tracks_path(@conference.short_title)
- if can? :update, @conference.event_types.build
%li{:class=> active_nav_li(admin_conference_event_types_path(@conference.short_title))}
= link_to 'Event types', admin_conference_event_types_path(@conference.short_title)
- if can? :update, @conference.difficulty_levels.build, conference_id: @conference.id
%li{:class=> active_nav_li(admin_conference_difficulty_levels_path(@conference.short_title))}
= link_to 'Difficulty levels', admin_conference_difficulty_levels_path(@conference.short_title)
- if can? :update, Question.new(conference_id: @conference.id)
%li{:class=> active_nav_li(admin_conference_questions_path(@conference.short_title))}
= link_to(admin_conference_questions_path(@conference.short_title)) do
%span.glyphicon.glyphicon-question-sign
Questions
- if can? :manage, @conference
%li{:class=> active_nav_li(roles_admin_conference_path(@conference.short_title))}
= link_to 'Roles', roles_admin_conference_path(@conference.short_title)

View file

@ -10,17 +10,20 @@
%span.glyphicon.glyphicon-home
All Conferences
- @conferences.each do |conference|
- if can? :show, conference
%li
= link_to(admin_conference_path(conference.short_title)) do
%span.glyphicon.glyphicon-cog
Manage
= conference.short_title
- if (current_user.is_admin) || (current_user.has_role? :organizer, :any)
%li
= link_to(admin_conference_path(conference.short_title)) do
%span.glyphicon.glyphicon-cog
Manage
= conference.short_title
%li
= link_to(new_admin_conference_path) do
%span.glyphicon.glyphicon-plus
New Conference
%hr
%li
= link_to(admin_users_path) do
%span.glyphicon.glyphicon-user
Users
= link_to(new_admin_conference_path) do
%span.glyphicon.glyphicon-plus
New Conference
- if can? :index, User
%hr
%li
= link_to(admin_users_path) do
%span.glyphicon.glyphicon-user
Users

View file

@ -11,13 +11,13 @@
= link_to(destroy_user_session_path, :method=>'delete') do
%span.glyphicon.glyphicon-minus
Sign out
-if has_role?(current_user, "admin") || has_role?(current_user, "organizer")
- if can? :index, Conference
%li.divider
%li
= link_to(admin_conference_index_path()) do
%span.glyphicon.glyphicon-home
Administration
-if @conference and @conference.id
-if @conference and @conference.id and can? :show, @conference
%li
= link_to(admin_conference_path(@conference.short_title)) do
%span.glyphicon.glyphicon-cog

View file

@ -26,11 +26,14 @@
= commercial.commercial_type
.flexvideo
= render partial: 'shared/media_item', locals: { commercial_type: commercial.commercial_type, commercial_id: commercial.commercial_id }
= link_to 'Edit', edit_conference_proposal_commercial_path(@conference.short_title, @event.id, commercial.id), class: 'btn btn-primary'
= link_to 'Delete', conference_proposal_commercial_path(@conference.short_title, @event.id, commercial.id),
- if can? :update, commercial
= link_to 'Edit', edit_conference_proposal_commercial_path(@conference.short_title, @event.id, commercial.id), class: 'btn btn-primary'
- if can? :destrooy, commercial
= link_to 'Delete', conference_proposal_commercial_path(@conference.short_title, @event.id, commercial.id),
:method => :delete, :data => { :confirm => 'Are you sure?' }, class: 'btn btn-danger'
%hr
= link_to 'Add Commercial', new_conference_proposal_commercial_path(@conference.short_title, @event.id), class: 'btn btn-primary'
- if can? :create, @event.commercials.new
%hr
= link_to 'Add Commercial', new_conference_proposal_commercial_path(@conference.short_title, @event.id), class: 'btn btn-primary'
#attachment-content.tab-pane
= form_for EventAttachment.new, :url => conference_proposal_event_attachment_index_path(@conference.short_title, @event), :html => { :multipart => true, :id => "fileupload" } do |f|
@ -68,7 +71,7 @@
data.formData = inputs.serializeArray();
});
$.getJSON($('#fileupload').prop('action'), function (files) {
var fu = $('#fileupload').data('fileupload'),
var fu = $('#fileupload').data('blueimpFileupload'),
template;
fu._adjustMaxNumberOfFiles(-files.length);
template = fu._renderDownload(files)

View file

@ -1,20 +1,20 @@
= semantic_form_for(@event, :url => @url) do |f|
%section#basic
= f.inputs :name => "Session Information" do
- if !@conference.call_for_papers.schedule_changes && @event.state == "confirmed" && !organizer_or_admin?
- if can? :update, @event or can? :create, @event
= f.input :title, :as => :string, :required => true
- else
Title: #{@event.title}
%br
%br
- else
= f.input :title, :as => :string, :required => true
= f.input :subtitle, :as => :string
%section#details
- if (@event.state === "unconfirmed" || @event.state === "confirmed") && !organizer_or_admin? && !@conference.call_for_papers.schedule_changes
- if can? :update, @event or can? :create, @event
= f.input :event_type_id,:as => :select, :collection => @conference.event_types.map {|x| ["#{x.title} - #{show_time(x.length)}", x.id]}, :include_blank => false, :label => "Session Type"
- else
Event type: #{@event.event_type.title}
%br
%br
- else
= f.input :event_type_id,:as => :select, :collection => @conference.event_types.map {|x| ["#{x.title} - #{show_time(x.length)}", x.id]}, :include_blank => false, :label => "Session Type"
= f.input :difficulty_level, :as => :select, :collection => @conference.difficulty_levels, :include_blank => "(Please select)" if @conference.use_difficulty_levels
= f.input :require_registration
= f.input :abstract, :input_html => {:rows => 5, :class => "span11"},

View file

@ -2,7 +2,7 @@
.col-md-12.page-header
%h1
= "My Proposals for #{@conference.title}"
- if @conference.cfp_open? || organizer_or_admin?
- if @conference.cfp_open? || (current_user.has_role? :organizer, @conference)
= link_to "New Proposal", new_conference_proposal_path(@conference.short_title), :class => "btn btn-success pull-right"
- if current_user.proposal_count(@conference) > 0
.row
@ -27,7 +27,7 @@
(Pre-registered: #{pre_registered(event).count})
- if event.confirmed? && !@conference.user_registered?(current_user)
%br
= link_to "Register to attend", register_conference_path(@conference.short_title), :style => "font-size:10px;"
= link_to "Register to attend", conference_register_path(@conference.short_title), :style => "font-size:10px;"
%td
.pull-right
- if event.transition_possible? :confirm

View file

@ -1,6 +1,6 @@
.row
.col-md-12
= simple_format(@conference.call_for_papers.description)
= simple_format(@conference.call_for_papers.description) if @conference.call_for_papers
.row
.col-md-12
= render 'proposal_form'

View file

@ -7,7 +7,7 @@
%small
= @event.subtitle
= link_to "Schedule", conference_schedule_path(@conference.short_title), :class =>"btn btn-success pull-right"
- if has_role?(current_user, "admin")
- if can? :edit, @event
= link_to "Edit", edit_admin_conference_event_path(@conference.short_title, @event), :class => "btn btn-mini btn-primary pull-right"
.row
.col-md-3
@ -37,7 +37,7 @@
%span.label{:style =>"background-color: #{@event.difficulty_level.color};"}
= @event.difficulty_level.title
- if @event.require_registration
= link_to "Registration required!", register_conference_path(@conference.short_title), :class => "btn btn-xs btn-warning"
= link_to "Registration required!", conference_register_path(@conference.short_title), :class => "btn btn-xs btn-warning"
.col-md-9
.row
.col-md-12

View file

@ -0,0 +1,8 @@
Rolify.configure do |config|
# By default ORM adapter is ActiveRecord. uncomment to use mongoid
# config.use_mongoid
# Dynamic shortcuts for User class (user.is_admin? like methods). Default is: false
# Enable this feature _after_ running rake db:migrate as it relies on the roles table
config.use_dynamic_shortcuts
end

View file

@ -8,8 +8,13 @@ Osem::Application.routes.draw do
resources :users
resources :people
resources :conference do
resource :contact, except: [:index, :new, :create, :show, :destroy]
resources :photos, except: [:show]
member do
get :roles
post :roles
post :add_user
delete :remove_user
end
resource :contact, except: [:index, :new, :create]
resource :schedule, only: [:show, :update]
resources :commercials, except: [:show]
get '/stats' => 'stats#index'
@ -40,7 +45,7 @@ Osem::Application.routes.draw do
resources :campaigns
resources :eventtypes, only: [:show, :index] do
resources :event_types, only: [:show, :index] do
collection do
patch :update
end
@ -92,10 +97,10 @@ Osem::Application.routes.draw do
resource :schedule, only: [] do
get "/" => "schedule#index"
end
get "/register" => "conference_registration#register"
patch "/register" => "conference_registration#update"
delete "/register" => "conference_registration#unregister"
member do
get "/register" => "conference_registration#register"
patch "/register" => "conference_registration#update"
delete "/register" => "conference_registration#unregister"
get "gallery_photos"
patch "subscription" => "conference#subscribe"
delete "subscription" => "conference#unsubscribe"

View file

@ -0,0 +1,10 @@
class AddDescriptionAndResourceToRoles < ActiveRecord::Migration
def change
add_column :roles, :description, :string
add_reference :roles, :resource, polymorphic: true
add_index(:roles, :name)
add_index(:roles, [:name, :resource_type, :resource_id])
add_index(:roles_users, [:user_id, :role_id])
end
end

View file

@ -0,0 +1,5 @@
class AddIsAdminToUsers < ActiveRecord::Migration
def change
add_column :users, :is_admin, :boolean
end
end

View file

@ -363,15 +363,23 @@ ActiveRecord::Schema.define(version: 20140801170430) do
create_table "roles", force: true do |t|
t.string "name"
t.string "description"
t.integer "resource_id"
t.string "resource_type"
t.datetime "created_at"
t.datetime "updated_at"
end
add_index "roles", ["name", "resource_type", "resource_id"], name: "index_roles_on_name_and_resource_type_and_resource_id"
add_index "roles", ["name"], name: "index_roles_on_name"
create_table "roles_users", id: false, force: true do |t|
t.integer "role_id"
t.integer "user_id"
end
add_index "roles_users", ["user_id", "role_id"], name: "index_roles_users_on_user_id_and_role_id"
create_table "rooms", force: true do |t|
t.string "guid", null: false
t.integer "conference_id"
@ -484,6 +492,7 @@ ActiveRecord::Schema.define(version: 20140801170430) do
t.string "tshirt"
t.string "languages"
t.text "volunteer_experience"
t.boolean "is_admin"
end
add_index "users", ["confirmation_token"], name: "index_users_on_confirmation_token", unique: true

View file

@ -5,18 +5,18 @@
#
# cities = City.create([{ name: 'Chicago' }, { name: 'Copenhagen' }])
# Mayor.create(name: 'Emanuel', city: cities.first)
Role.create(name: "Participant")
Role.create(name: "Organizer")
Role.create(name: "Admin")
qtype_yesno = QuestionType.create(title: "Yes/No")
QuestionType.create(title: "Single Choice")
QuestionType.create(title: "Multiple Choice")
# Questions
qtype_yesno = QuestionType.create(title: 'Yes/No')
qtype_single = QuestionType.create(title: 'Single Choice')
qtype_multiple = QuestionType.create(title: 'Multiple Choice')
answer_yes = Answer.create(title: "Yes")
answer_no = Answer.create(title: "No")
answer_yes = Answer.create(title: 'Yes')
answer_no = Answer.create(title: 'No')
questions_yes_no = ["Do you need handicapped access to the venue?", "Are you attending with partner?", "Will you attend the social event(s)?", "Will you stay at suggested hotel?"]
questions_yes_no = ['Do you need handicapped access to the venue?',
'Are you attending with partner?', 'Will you attend the social event(s)?',
'Will you stay at suggested hotel?']
questions_yes_no.each do |i|
q = Question.create(title: i, question_type_id: qtype_yesno.id, global: true)

View file

@ -3,16 +3,15 @@ require 'spec_helper'
describe Admin::ConferenceController do
# It is necessary to use bang version of let to build roles before user
let!(:organizer_role) { create(:organizer_role) }
let!(:participant_role) { create(:participant_role) }
let!(:admin_role) { create(:admin_role) }
let(:conference) { create(:conference) }
let(:admin) { create(:admin) }
let(:organizer) { create(:organizer) }
let!(:first_user) { create(:user) }
let!(:participant_role) { create(:participant_role) }
let!(:organizer_role) { create(:role, name: 'organizer', resource: conference) }
let(:organizer) { create(:user, role_ids: organizer_role.id, is_admin: true) }
let(:participant) { create(:participant) }
shared_examples 'access as administration or organizer' do
shared_examples 'access as administration' do
describe 'PATCH #update' do
@ -45,8 +44,7 @@ describe Admin::ConferenceController do
mailer = double
allow(mailer).to receive(:deliver)
conference.email_settings = create(:email_settings)
patch :update, id: conference.short_title, conference:
attributes_for(:conference, start_date: Date.today + 2.days, end_date: Date.today + 4.days)
patch :update, id: conference.short_title#, conference: attributes_for(:conference, start_date: Date.today + 2.days, end_date: Date.today + 4.days)
conference.reload
allow(Mailbot).to receive(:conference_date_update_mail).and_return(mailer)
end
@ -193,8 +191,12 @@ describe Admin::ConferenceController do
context 'no conferences' do
it 'redirect to new conference' do
Conference.all.each do |c|
c.destroy
end
sign_in create(:admin)
get :index
expect(response).to redirect_to(redirect_to new_admin_conference_path)
expect(response).to redirect_to new_admin_conference_path
end
end
end
@ -215,59 +217,64 @@ describe Admin::ConferenceController do
describe 'administrator access' do
before do
sign_in(admin)
end
it_behaves_like 'access as administration or organizer'
end
describe 'organizer access' do
before(:each) do
sign_in(organizer)
end
it_behaves_like 'access as administration or organizer'
it_behaves_like 'access as administration'
end
shared_examples 'access as participant or guest' do |success_path|
shared_examples 'access as participant or guest' do |path, message|
describe 'GET #show' do
it 'requires admin privileges' do
it 'requires organizer privileges' do
get :show, id: conference.short_title
expect(response).to redirect_to(send(success_path))
expect(response).to redirect_to(send(path))
if message
expect(flash[:alert]).to match(/#{message}/)
end
end
end
describe 'GET #index' do
it 'requires admin privileges' do
it 'requires organizer privileges' do
get :index
expect(response).to redirect_to(send(success_path))
expect(response).to redirect_to(send(path))
if message
expect(flash[:alert]).to match(/#{message}/)
end
end
end
describe 'GET #new' do
it 'requires admin privileges' do
it 'requires organizer privileges' do
get :new
expect(response).to redirect_to(send(success_path))
expect(response).to redirect_to(send(path))
if message
expect(flash[:alert]).to match(/#{message}/)
end
end
end
describe 'POST #create' do
it 'requires admin privileges' do
it 'requires organizer privileges' do
post :create, conference: attributes_for(:conference,
short_title: 'ExCon')
expect(response).to redirect_to(send(success_path))
expect(response).to redirect_to(send(path))
if message
expect(flash[:alert]).to match(/#{message}/)
end
end
end
describe 'PATCH #update' do
it 'requires admin privileges' do
it 'requires organizer privileges' do
patch :update, id: conference.short_title,
conference: attributes_for(:conference,
short_title: 'ExCon')
expect(response).to redirect_to(send(success_path))
expect(response).to redirect_to(send(path))
if message
expect(flash[:alert]).to match(/#{message}/)
end
end
end
end
@ -277,7 +284,7 @@ describe Admin::ConferenceController do
sign_in(participant)
end
it_behaves_like 'access as participant or guest', :root_path
it_behaves_like 'access as participant or guest', :root_path, 'You are not authorized to access this area!'
end

View file

@ -1,7 +1,5 @@
require 'spec_helper'
describe Admin::UsersController do
let!(:admin_role) { create(:admin_role) }
let!(:participant_role) { create(:participant_role) }
let(:admin) { create(:admin) }
let(:user) { create(:user) }
before(:each) do
@ -31,7 +29,7 @@ describe Admin::UsersController do
:user, email: 'example@incoherent.de', id: user.id).email).
to eq('example@incoherent.de')
end
it "redirects to the updated user" do
it 'redirects to the updated user' do
patch :update, id: user.id
expect(response).to redirect_to admin_users_path
end

View file

@ -1,7 +1,8 @@
require 'spec_helper'
describe ConferenceController do
let(:conference) { create(:conference) }
let(:conference) { create(:conference, make_conference_public: true) }
describe 'GET #show' do
context 'conference made public' do
it 'assigns the requested conference to conference' do
@ -24,7 +25,7 @@ describe ConferenceController do
it 'renders flash saying conference not ready' do
get :show, id: conference.short_title
expect(flash[:notice]).to eq("Conference not ready yet!!")
expect(flash[:alert]).to eq('You are not authorized to access this page.')
end
end
context 'gallery photos for splash' do

View file

@ -0,0 +1,8 @@
# Read about factories at https://github.com/thoughtbot/factory_girl
FactoryGirl.define do
factory :commercial do
commercial_type 'YouTube'
commercial_id 'test'
end
end

View file

@ -1,16 +1,18 @@
FactoryGirl.define do
factory :role do
factory :admin_role do
name 'Admin'
factory :participant_role do
name 'participant'
end
factory :organizer_role do
name 'Organizer'
name 'organizer'
end
factory :participant_role do
name 'Participant'
factory :organizer_conference_1_role do
name 'organizer'
resource_type 'Conference'
resource_id 1
end
end
end

View file

@ -19,12 +19,12 @@ FactoryGirl.define do
after(:create) { |user| user.role_ids = create(:participant_role).id }
end
factory :admin do
after(:create) { |user| user.role_ids = create(:admin_role).id }
factory :organizer_conference_1 do
after(:create) { |user| user.role_ids = create(:organizer_conference_1_role).id }
end
factory :organizer do
after(:create) { |user| user.role_ids = create(:organizer_role).id }
factory :admin do
is_admin true
end
end
end

View file

@ -0,0 +1,266 @@
require 'spec_helper'
feature 'Has correct abilities' do
# It is necessary to use bang version of let to build roles before user
let(:conference1) { create(:conference) } # user is organizer
let(:conference2) { create(:conference) } # user is cfp
let(:conference3) { create(:conference) } # user is info_desk
let(:conference4) { create(:conference) } # user is volunteer coordinator
let(:conference5) { create(:conference) } # user has no role
let(:role_organizer) { create(:role, name: 'organizer', resource: conference1) }
let(:role_cfp) { create(:role, name: 'cfp', resource: conference2) }
let(:role_info_desk) { create(:role, name: 'info_desk', resource: conference3) }
let(:role_volunteer_coordinator) { create(:role, name: 'volunteer_coordinator', resource: conference4) }
let(:user) { create(:user, role_ids: [role_organizer.id, role_cfp.id, role_info_desk.id, role_volunteer_coordinator.id]) }
scenario 'when user is organizer' do
sign_in user
visit admin_conference_path(conference1.short_title)
expect(page.has_content?('Settings')).to be true
expect(page.has_content?('Manage')).to be true
expect(page.has_content?('Registrations')).to be true
expect(page.has_content?('Events')).to be true
expect(page.has_content?('Schedule')).to be true
expect(page.has_content?('Campaigns')).to be true
expect(page.has_content?('Targets')).to be true
expect(page.has_content?('Venue')).to be true
expect(page.has_content?('Sponsorship')).to be true
expect(page.has_content?('Supporter Levels')).to be true
expect(page.has_content?('E-Mails')).to be true
expect(page.has_content?('Call for papers')).to be true
expect(page.has_content?('Questions')).to be true
expect(page.has_content?('Commercials')).to be true
visit edit_admin_conference_path(conference1.short_title)
expect(current_path).to eq(edit_admin_conference_path(conference1.short_title))
visit admin_conference_path(conference1.short_title)
expect(current_path).to eq(admin_conference_path(conference1.short_title))
visit admin_conference_registrations_path(conference1.short_title)
expect(current_path).to eq(admin_conference_registrations_path(conference1.short_title))
visit admin_conference_events_path(conference1.short_title)
expect(current_path).to eq(admin_conference_events_path(conference1.short_title))
visit admin_conference_schedule_path(conference1.short_title)
expect(current_path).to eq(admin_conference_schedule_path(conference1.short_title))
visit admin_conference_campaigns_path(conference1.short_title)
expect(current_path).to eq(admin_conference_campaigns_path(conference1.short_title))
visit admin_conference_targets_path(conference1.short_title)
expect(current_path).to eq(admin_conference_targets_path(conference1.short_title))
visit admin_conference_venue_info_path(conference1.short_title)
expect(current_path).to eq(admin_conference_venue_info_path(conference1.short_title))
visit admin_conference_sponsorship_levels_path(conference1.short_title)
expect(current_path).to eq(admin_conference_sponsorship_levels_path(conference1.short_title))
visit admin_conference_supporter_levels_path(conference1.short_title)
expect(current_path).to eq(admin_conference_supporter_levels_path(conference1.short_title))
visit admin_conference_emails_path(conference1.short_title)
expect(current_path).to eq(admin_conference_emails_path(conference1.short_title))
visit admin_conference_callforpapers_path(conference1.short_title)
expect(current_path).to eq(admin_conference_callforpapers_path(conference1.short_title))
visit admin_conference_questions_path(conference1.short_title)
expect(current_path).to eq(admin_conference_questions_path(conference1.short_title))
visit admin_conference_commercials_path(conference1.short_title)
expect(current_path).to eq(admin_conference_commercials_path(conference1.short_title))
end
scenario 'when user is cfp' do
sign_in user
visit admin_conference_path(conference2.short_title)
expect(page.has_content?('Settings')).to be false
expect(page.has_content?('Manage')).to be true
# expect(page.has_content?('Registrations')).to be false
expect(page.has_content?('Events')).to be true
expect(page.has_content?('Schedule')).to be true
# expect(page.has_content?('Campaigns')).to be false
expect(page.has_content?('Targets')).to be false
expect(page.has_content?('Venue')).to be true
expect(page.has_content?('Sponsorship')).to be false
expect(page.has_content?('Supporter Levels')).to be false
expect(page.has_content?('E-Mails')).to be true
expect(page.has_content?('Call for papers')).to be true
expect(page.has_content?('Questions')).to be false
expect(page.has_content?('Commercials')).to be true
visit edit_admin_conference_path(conference2.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_path(conference2.short_title)
expect(current_path).to eq(admin_conference_path(conference2.short_title))
visit admin_conference_registrations_path(conference2.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_events_path(conference2.short_title)
expect(current_path).to eq(admin_conference_events_path(conference2.short_title))
visit admin_conference_schedule_path(conference2.short_title)
expect(current_path).to eq(admin_conference_schedule_path(conference2.short_title))
visit admin_conference_campaigns_path(conference2.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_targets_path(conference2.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_venue_info_path(conference2.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_sponsorship_levels_path(conference2.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_supporter_levels_path(conference2.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_emails_path(conference2.short_title)
expect(current_path).to eq(admin_conference_emails_path(conference2.short_title))
visit admin_conference_callforpapers_path(conference2.short_title)
expect(current_path).to eq(admin_conference_callforpapers_path(conference2.short_title))
visit admin_conference_questions_path(conference2.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_commercials_path(conference3.short_title)
expect(current_path).to eq(admin_conference_commercials_path(conference3.short_title))
end
scenario 'when user is info desk' do
sign_in user
visit admin_conference_path(conference3.short_title)
expect(page.has_content?('Settings')).to be false
expect(page.has_content?('Manage')).to be true
expect(page.has_content?('Registrations')).to be true
expect(page.has_content?('Events')).to be false
expect(page.has_content?('Schedule')).to be false
# expect(page.has_content?('Campaigns')).to be false
expect(page.has_content?('Targets')).to be false
expect(page.has_content?('Venue')).to be false
expect(page.has_content?('Sponsorship')).to be false
expect(page.has_content?('Supporter Levels')).to be false
expect(page.has_content?('E-Mails')).to be false
expect(page.has_content?('Call for papers')).to be false
expect(page.has_content?('Questions')).to be true
expect(page.has_content?('Commercials')).to be true
visit edit_admin_conference_path(conference3.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_path(conference3.short_title)
expect(current_path).to eq(admin_conference_path(conference3.short_title))
visit admin_conference_registrations_path(conference3.short_title)
expect(current_path).to eq(admin_conference_registrations_path(conference3.short_title))
visit admin_conference_events_path(conference3.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_schedule_path(conference3.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_campaigns_path(conference3.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_targets_path(conference3.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_venue_info_path(conference3.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_sponsorship_levels_path(conference3.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_supporter_levels_path(conference3.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_emails_path(conference3.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_callforpapers_path(conference3.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_questions_path(conference3.short_title)
expect(current_path).to eq(admin_conference_questions_path(conference3.short_title))
visit admin_conference_commercials_path(conference3.short_title)
expect(current_path).to eq(admin_conference_commercials_path(conference3.short_title))
end
scenario 'when user is volunteer coordinator' do
sign_in user
visit admin_conference_path(conference4.short_title)
expect(page.has_content?('Settings')).to be false
expect(page.has_content?('Manage')).to be true
# expect(page.has_content?('Registrations')).to be false
expect(page.has_content?('Events')).to be false
expect(page.has_content?('Schedule')).to be false
# expect(page.has_content?('Campaigns')).to be false
expect(page.has_content?('Targets')).to be false
expect(page.has_content?('Venue')).to be false
expect(page.has_content?('Sponsorship')).to be false
expect(page.has_content?('Supporter Levels')).to be false
expect(page.has_content?('E-Mails')).to be false
expect(page.has_content?('Call for papers')).to be false
expect(page.has_content?('Questions')).to be false
expect(page.has_content?('Commercials')).to be true
visit edit_admin_conference_path(conference4.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_path(conference4.short_title)
expect(current_path).to eq(admin_conference_path(conference4.short_title))
visit admin_conference_registrations_path(conference4.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_events_path(conference4.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_schedule_path(conference4.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_campaigns_path(conference4.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_targets_path(conference4.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_venue_info_path(conference4.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_sponsorship_levels_path(conference4.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_supporter_levels_path(conference4.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_emails_path(conference4.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_callforpapers_path(conference4.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_questions_path(conference4.short_title)
expect(current_path).to eq(root_path)
visit admin_conference_commercials_path(conference3.short_title)
expect(current_path).to eq(admin_conference_commercials_path(conference3.short_title))
end
end

View file

@ -3,9 +3,8 @@ require 'spec_helper'
feature Campaign do
# It is necessary to use bang version of let to build roles before user
let!(:organizer_role) { create(:organizer_role) }
let!(:participant_role) { create(:participant_role) }
let!(:admin_role) { create(:admin_role) }
let!(:organizer_conference_1_role) { create(:organizer_conference_1_role) }
shared_examples 'add and update campaign' do |user|
scenario 'adds and update a campaign', feature: true, js: true do
@ -42,7 +41,7 @@ feature Campaign do
expect(Campaign.count).to eq(expected_count)
campaign = Campaign.where('name'=> 'Test Campaign').first
campaign = Campaign.where('name' => 'Test Campaign').first
visit edit_admin_conference_campaign_path(conference.short_title, campaign.id)
fill_in 'campaign_name', with: 'Test Campaign 42'
@ -52,8 +51,7 @@ feature Campaign do
end
end
describe 'admin' do
it_behaves_like 'add and update campaign', :admin
it_behaves_like 'add and update campaign', :organizer
describe 'organizer' do
it_behaves_like 'add and update campaign', :organizer_conference_1
end
end

View file

@ -3,9 +3,8 @@ require 'spec_helper'
feature Conference do
# It is necessary to use bang version of let to build roles before user
let!(:organizer_role) { create(:organizer_role) }
let!(:participant_role) { create(:participant_role) }
let!(:admin_role) { create(:admin_role) }
let!(:organizer_conference_1_role) { create(:organizer_conference_1_role) }
shared_examples 'add and update cfp' do |user|
scenario 'adds a new cfp', feature: true, js: true do
@ -87,8 +86,7 @@ feature Conference do
end
end
describe 'admin' do
it_behaves_like 'add and update cfp', :admin
it_behaves_like 'add and update cfp', :organizer
describe 'organizer' do
it_behaves_like 'add and update cfp', :organizer_conference_1
end
end

View file

@ -2,18 +2,17 @@ require 'spec_helper'
feature Commercial do
# It is necessary to use bang version of let to build roles before user
let!(:organizer_role) { create(:organizer_role) }
let!(:participant_role) { create(:participant_role) }
let!(:admin_role) { create(:admin_role) }
let!(:conference) { create(:conference) }
let!(:organizer_role) { create(:role, name: 'organizer', resource: conference) }
let!(:organizer) { create(:user, role_ids: [organizer_role.id]) }
shared_examples 'adds and updates a commercial' do |user|
shared_examples 'adds and updates a commercial' do
scenario 'of a conference',
feature: true, js: true do
conference = create(:conference)
expected_count = conference.commercials.count + 1
sign_in create(user)
sign_in organizer
visit admin_conference_commercials_path(conference.short_title)
@ -61,11 +60,7 @@ feature Commercial do
end
end
describe 'admin' do
it_behaves_like 'adds and updates a commercial', :admin
end
describe 'organizer' do
it_behaves_like 'adds and updates a commercial', :organizer
it_behaves_like 'adds and updates a commercial'
end
end

View file

@ -3,9 +3,8 @@ require 'spec_helper'
feature Conference do
# It is necessary to use bang version of let to build roles before user
let!(:organizer_role) { create(:organizer_role) }
let!(:participant_role) { create(:participant_role) }
let!(:admin_role) { create(:admin_role) }
let!(:organizer_conference_1_role) { create(:organizer_conference_1_role) }
shared_examples 'add and update conference' do |user|
scenario 'adds a new conference', feature: true, js: true do
@ -36,7 +35,7 @@ feature Conference do
scenario 'update conference', feature: true, js: true do
conference = create(:conference)
expected_count = Conference.count
sign_in create(user)
sign_in create(:organizer_conference_1)
visit edit_admin_conference_path(conference.short_title)
click_link 'Edit'
@ -65,9 +64,4 @@ feature Conference do
describe 'admin' do
it_behaves_like 'add and update conference', :admin
end
describe 'organizer' do
it_behaves_like 'add and update conference', :organizer
end
end

View file

@ -2,9 +2,8 @@ require 'spec_helper'
feature DifficultyLevel do
# It is necessary to use bang version of let to build roles before user
let!(:organizer_role) { create(:organizer_role) }
let!(:participant_role) { create(:participant_role) }
let!(:admin_role) { create(:admin_role) }
let!(:organizer_conference_1_role) { create(:organizer_conference_1_role) }
shared_examples 'difficulty levels' do |user|
scenario 'adds and updates difficulty level', feature: true, js: true do
@ -50,11 +49,7 @@ feature DifficultyLevel do
end
end
describe 'admin' do
it_behaves_like 'difficulty levels', :admin
end
describe 'organizer' do
it_behaves_like 'difficulty levels', :organizer
it_behaves_like 'difficulty levels', :organizer_conference_1
end
end

View file

@ -2,9 +2,8 @@ require 'spec_helper'
feature EmailSettings do
# It is necessary to use bang version of let to build roles before user
let!(:organizer_role) { create(:organizer_role) }
let!(:participant_role) { create(:participant_role) }
let!(:admin_role) { create(:admin_role) }
let!(:organizer_conference_1_role) { create(:organizer_conference_1_role) }
shared_examples 'email settings' do |user|
scenario 'updates email settings',
@ -91,11 +90,7 @@ feature EmailSettings do
end
end
describe 'admin' do
it_behaves_like 'email settings', :admin
end
describe 'organizer' do
it_behaves_like 'email settings', :organizer
it_behaves_like 'email settings', :organizer_conference_1
end
end

View file

@ -2,15 +2,14 @@ require 'spec_helper'
feature EventType do
# It is necessary to use bang version of let to build roles before user
let!(:organizer_role) { create(:organizer_role) }
let!(:participant_role) { create(:participant_role) }
let!(:admin_role) { create(:admin_role) }
let!(:organizer_conference_1_role) { create(:organizer_conference_1_role) }
shared_examples 'event types' do |user|
scenario 'adds and updates event type', feature: true, js: true do
conference = create(:conference)
sign_in create(user)
visit admin_conference_eventtypes_path(
visit admin_conference_event_types_path(
conference_id: conference.short_title)
expect(page.all('div.nested-fields').count == 2).to be true
@ -55,11 +54,7 @@ feature EventType do
end
end
describe 'admin' do
it_behaves_like 'event types', :admin
end
describe 'organizer' do
it_behaves_like 'event types', :organizer
it_behaves_like 'event types', :organizer_conference_1
end
end

View file

@ -2,9 +2,8 @@ require 'spec_helper'
feature Lodging do
# It is necessary to use bang version of let to build roles before user
let!(:organizer_role) { create(:organizer_role) }
let!(:participant_role) { create(:participant_role) }
let!(:admin_role) { create(:admin_role) }
let!(:organizer_conference_1_role) { create(:organizer_conference_1_role) }
shared_examples 'lodgings' do |user|
scenario 'adds and updates lodgings', feature: true, js: true do
@ -56,11 +55,7 @@ feature Lodging do
end
end
describe 'admin' do
it_behaves_like 'lodgings', :admin
end
describe 'organizer' do
it_behaves_like 'lodgings', :organizer
it_behaves_like 'lodgings', :organizer_conference_1
end
end

Some files were not shown because too many files have changed in this diff Show more